PT-2009-5826 · Clear Content · Clear Content

Mizoz

·

Publicado

2009-10-02

·

Atualizado

2017-09-19

·

CVE-2009-3535

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Clear Content version 1.1
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the url parameter of the image.php file.
Recommendations For Clear Content version 1.1, consider restricting access to the image.php file until a patch is available, or apply configuration changes to prevent directory traversal attacks, such as validating and sanitizing the url parameter to prevent the inclusion of malicious input.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3535

Produtos afetados

Clear Content