PT-2007-7103 · Learnloop · Learnloop

Gold_M

·

Published

2007-12-04

·

Updated

2017-09-29

·

CVE-2007-6214

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions LearnLoop version 2.0 beta7
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files by utilizing a .. (dot dot) in the sFilePath parameter of the include/file download.php file. This issue can be exploited if the product is configured but has no files in the database.
Recommendations For LearnLoop version 2.0 beta7, consider restricting access to the include/file download.php file or the sFilePath parameter to minimize the risk of exploitation. Avoid using the sFilePath parameter with unvalidated input until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6214

Affected Products

Learnloop