PT-2015-4284 · Fluxbb · Fluxbb
Publicado
2015-02-03
·
Atualizado
2017-09-08
·
CVE-2014-9574
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FluxBB versions prior to 1.5.8
Description
The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the
install lang parameter in the install.php file.Recommendations
For versions prior to 1.5.8, update to version 1.5.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the install.php file until the update is applied.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fluxbb