PT-2007-1395 · Kubix · Kubix

Blackhawk

·

Published

2007-03-06

·

Updated

2017-10-11

·

CVE-2006-7117

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kubix versions 0.7 and earlier
Description The issue allows remote attackers to perform directory traversal attacks. This can be achieved in two ways: (1) by including and executing arbitrary local files via ".." sequences in the theme cookie to "index.php", which is not properly handled by "includes/head.php"; and (2) by reading arbitrary files via ".." sequences in the file parameter in an "add dl" action to "adm index.php". For example, an attacker could read "connect.php" using this method.
Recommendations For Kubix versions 0.7 and earlier, consider disabling access to the "index.php" and "adm index.php" files until a patch is available. Restrict the use of the theme cookie and the file parameter in the "add dl" action to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-7117

Affected Products

Kubix