PT-2007-3757 · Imageview · Imageview
Dnx
·
Published
2007-05-02
·
Updated
2017-10-11
·
CVE-2007-2425
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Imageview version 5.3
Description
A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved by using a .. (dot dot) in the
album parameter of the fileview.php file.Recommendations
For Imageview version 5.3, consider restricting access to the fileview.php file until a patch is available, or apply configuration changes to prevent directory traversal attacks, such as validating and sanitizing user input for the
album parameter.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imageview