PT-2006-6269 · Unknown+2 · Albumview.Php+2
Kacper
·
Published
2006-10-26
·
Updated
2017-10-19
·
CVE-2006-5554
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Imageview version 5
Description:
A directory traversal issue exists, allowing remote attackers to read or execute arbitrary local files. This is achieved by using a .. (dot dot) in the
user settings cookie. Attackers can exploit this by uploading a text/plain .gif file containing PHP code via the MyFile parameter in "albumview.php", which is then executed by "index.php".Recommendations:
For Imageview version 5, consider restricting access to the
albumview.php file and avoid using the MyFile parameter until a patch is available. As a temporary workaround, restrict the use of the user settings cookie to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imageview
Albumview.Php
Index.Php