PT-2003-2405 · Unknown · Worker Filemanager
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1460
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Worker Filemanager versions 1.0 through 2.7
Description
The issue allows local users to obtain sensitive information due to the software setting permissions on the destination directory to world-readable and executable while copying data.
Recommendations
For versions 1.0 through 2.7, consider changing the permissions on the destination directory to restrict access and prevent sensitive information disclosure until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Worker Filemanager