PT-2015-7401 · Sitefactory · Sitefactory Cms
Publicado
2015-09-11
·
Atualizado
2015-09-14
·
CVE-2015-6914
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SiteFactory CMS version 5.5.9
Description
The issue allows remote attackers to read arbitrary files by providing a full pathname in the
file parameter to the "assets/download.aspx" API endpoint.Recommendations
For SiteFactory CMS version 5.5.9, consider restricting access to the "assets/download.aspx" endpoint until a patch is available, and avoid using the
file parameter with full pathnames to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sitefactory Cms