PT-2006-1319 · Phpxplorer · Phpxplorer
Oriol Torrent Santiago
·
Published
2006-01-18
·
Updated
2024-08-07
·
CVE-2006-0244
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
phpXplorer version 0.9.33
Description
A directory traversal issue in workspaces.php allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the
sShare parameter. However, it is claimed that this functionality is supported by phpXplorer for uploading PHP files and does not cross privilege boundaries due to the PHP functionality allowing read access outside the web root.Recommendations
For phpXplorer version 0.9.33, consider restricting access to the
sShare parameter in the workspaces.php file to minimize the risk of exploitation. Additionally, review the upload functionality to ensure it does not introduce security risks.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpxplorer