PT-2006-3709 · Iboutique · Iboutique+1
Luny
·
Published
2006-06-03
·
Updated
2018-10-18
·
CVE-2006-2791
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
iBoutique.MALL (affected versions not specified)
iBoutique (affected versions not specified)
Description
A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using ".." sequences in the
function parameter.Recommendations
For iBoutique.MALL, restrict access to the vulnerable
index.php file until a fix is available.
For iBoutique, consider disabling the index.php file as a temporary workaround until the issue is resolved.
Avoid using the function parameter in the index.php file with untrusted input until the vulnerability is fixed.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iboutique
Iboutique.Mall