PT-2019-10131 · Php Scripts Mall · Php Scripts Mall Advance B2B Script
Publicado
2019-03-20
·
Atualizado
2019-03-21
·
CVE-2018-20635
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
PHP Scripts Mall Advance B2B Script version 2.1.4
Description:
The issue allows directory traversal through a direct request for a listing of an image directory, such as an assets/ directory.
Recommendations:
For PHP Scripts Mall Advance B2B Script version 2.1.4, consider restricting access to sensitive directories to minimize the risk of exploitation.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php Scripts Mall Advance B2B Script