PT-2018-10556 · Bearadmin · Bearadmin
Kerlingcode
·
Publicado
2018-05-24
·
Atualizado
2018-06-25
·
CVE-2018-11413
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BearAdmin version 0.5
Description
An issue allows remote attackers to download arbitrary files via directory traversal sequences in the
/admin/databack/download.html endpoint, potentially exposing sensitive information such as MySQL credentials in the configuration file.Recommendations
For BearAdmin version 0.5, restrict access to the
/admin/databack/download.html endpoint to minimize the risk of exploitation. Consider implementing input validation and sanitization for the name parameter to prevent directory traversal attacks.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bearadmin