PT-2019-17845 · Shopxo · Shopxo

Qianxincodesafe

·

Publicado

2019-01-10

·

Atualizado

2019-01-18

·

CVE-2019-5887

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ShopXO version 1.2.0
Description An issue in the UnlinkDir method of the FileUtil.php file allows input mishandling by the rmdir method due to unchecked input parameters. This enables attackers to delete arbitrary files using "../" directory traversal.
Recommendations For ShopXO version 1.2.0, consider implementing input validation in the UnlinkDir method of the FileUtil.php file to prevent directory traversal attacks. As a temporary workaround, restrict access to the UnlinkDir method to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-5887

Produtos afetados

Shopxo