PT-2005-3834 · Php · Php Advanced Transfer Manager
Published
2005-09-20
·
Updated
2008-09-05
·
CVE-2005-2997
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Advanced Transfer Manager version 1.30
Description
The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This can be achieved by using ".." sequences in the
currentdir parameter to "txt.php", or the current dir parameter to "htm.php" or "html.php".Recommendations
For PHP Advanced Transfer Manager version 1.30, consider restricting access to the "txt.php", "htm.php", and "html.php" files until a patch is available. As a temporary workaround, avoid using the
currentdir and current dir parameters in the affected API endpoints.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php Advanced Transfer Manager