PT-2010-4952 · Netart Media · Netart Media Real Estate Portal

R0T

·

Publicado

2010-09-24

·

Atualizado

2017-08-17

·

CVE-2010-3606

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NetArt MEDIA Real Estate Portal version 2.0
Description The issue concerns directory traversal vulnerabilities in the AGENTS/index.php file. Remote attackers can exploit this to include and execute arbitrary local files by using directory traversal sequences in the folder and action parameters.
Recommendations For NetArt MEDIA Real Estate Portal version 2.0, restrict access to the folder and action parameters in the AGENTS/index.php file to minimize the risk of exploitation. Avoid using directory traversal sequences in these parameters until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3606

Produtos afetados

Netart Media Real Estate Portal