PT-2015-3691 · Impresscms · Impresscms
Publicado
2015-07-01
·
Atualizado
2022-05-17
·
CVE-2014-1836
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ImpressCMS versions prior to 1.3.6
Description
The issue allows remote attackers to delete arbitrary files via a full pathname in the
image path parameter in a cancel action. This is due to an absolute path traversal vulnerability in the htdocs/libraries/image-editor/image-edit.php file.Recommendations
For ImpressCMS versions prior to 1.3.6, update to version 1.3.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the htdocs/libraries/image-editor/image-edit.php file until a patch is available.
Avoid using the
image path parameter in the affected cancel action until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Impresscms