PT-2006-1319 · Phpxplorer · Phpxplorer

Oriol Torrent Santiago

·

Published

2006-01-18

·

Updated

2024-08-07

·

CVE-2006-0244

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpXplorer version 0.9.33
Description A directory traversal issue in workspaces.php allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. However, it is claimed that this functionality is supported by phpXplorer for uploading PHP files and does not cross privilege boundaries due to the PHP functionality allowing read access outside the web root.
Recommendations For phpXplorer version 0.9.33, consider restricting access to the sShare parameter in the workspaces.php file to minimize the risk of exploitation. Additionally, review the upload functionality to ensure it does not introduce security risks.

Exploit

Fix

Related Identifiers

CVE-2006-0244

Affected Products

Phpxplorer