PT-2010-4032 · Linker · Linker Img
Sn!Per.S!Te Hacker
·
Publicado
2010-06-25
·
Atualizado
2017-08-17
·
CVE-2010-2456
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linker IMG versions 1.0 and earlier
Description
The issue allows remote attackers to read and execute arbitrary local files. This can be achieved via a URL in the
cook lan cookie parameter, which is associated with the $lan dir variable, or possibly the Sdb type parameter.Recommendations
For versions 1.0 and earlier, consider restricting access to the
index.php file until a fix is available. As a temporary workaround, avoid using the cook lan cookie parameter and the Sdb type parameter in the affected URL.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linker Img