PT-2011-2864 · Focalmedia.Net · Focalmedia.Net Quick Polls

Mark Stanislav

·

Publicado

2011-03-09

·

Atualizado

2018-10-09

·

CVE-2011-1099

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions FocalMedia.Net Quick Polls versions prior to 1.0.2
Description The issue allows remote attackers to read or delete arbitrary files due to directory traversal vulnerabilities. This can be achieved by using a .. (dot dot) in the p parameter in either a preview or delete action to "index.php".
Recommendations For versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "index.php" file or disabling the preview and delete actions until a patch is available. Avoid using the p parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1099

Produtos afetados

Focalmedia.Net Quick Polls