PT-2009-6050 · Mobilelib · Mobilelib Gold

Qabandi

·

Publicado

2009-10-28

·

Atualizado

2017-09-19

·

CVE-2009-3823

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mobilelib GOLD version 3.0
Description The issue allows remote attackers to read arbitrary files due to a directory traversal vulnerability in the myhtml.php file. This occurs when magic quotes gpc is enabled and a .. (dot dot) is used in the GLOBALS[page] parameter.
Recommendations For Mobilelib GOLD version 3.0, consider disabling the use of the GLOBALS[page] parameter or restricting access to the myhtml.php file until a patch is available. As a temporary workaround, disabling magic quotes gpc may also help minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3823

Produtos afetados

Mobilelib Gold