PT-2015-7401 · Sitefactory · Sitefactory Cms

Publicado

2015-09-11

·

Atualizado

2015-09-14

·

CVE-2015-6914

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SiteFactory CMS version 5.5.9
Description The issue allows remote attackers to read arbitrary files by providing a full pathname in the file parameter to the "assets/download.aspx" API endpoint.
Recommendations For SiteFactory CMS version 5.5.9, consider restricting access to the "assets/download.aspx" endpoint until a patch is available, and avoid using the file parameter with full pathnames to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6914

Produtos afetados

Sitefactory Cms