PT-2010-2826 · Phpmysport · Phpmysport

Publicado

2010-03-25

·

Atualizado

2017-08-17

·

CVE-2010-1110

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions phpMySport version 1.4
Description A directory traversal issue exists, allowing remote attackers to list arbitrary directories. This is achieved by using a .. (dot dot) in the current folder parameter of the index.php file.
Recommendations For phpMySport version 1.4, consider restricting access to the current folder parameter in the index.php file to prevent directory traversal attacks. As a temporary workaround, avoid using the current folder parameter with untrusted input until a patch is available.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1110

Produtos afetados

Phpmysport