PT-2007-6777 · Ispworker · Ispworker

Gold_M

·

Published

2007-11-05

·

Updated

2017-09-29

·

CVE-2007-5813

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ISPworker version 1.21
Description The issue concerns multiple directory traversal vulnerabilities in the download.php file. Remote attackers can exploit this to read arbitrary files by including a .. (dot dot) in the ticketid and filename parameters.
Recommendations For ISPworker version 1.21, consider restricting access to the download.php file until a patch is available, and avoid using the ticketid and filename parameters in this file to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5813

Affected Products

Ispworker