PT-2008-5083 · Phpizabi · Phpizabi
Published
2008-08-20
·
Updated
2017-08-08
·
CVE-2008-3723
CVSS v2.0
6.3
Medium
| Vector | AV:N/AC:M/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PHPizabi version 0.848b C1 HFP3
Description
The issue allows remote authenticated administrators to read arbitrary files. This can be achieved via the
id parameter in an admin.templates.edittemplate action by using a .. (dot dot), a URL, or possibly a full pathname.Recommendations
For PHPizabi version 0.848b C1 HFP3, consider restricting access to the
admin.templates.edittemplate action to minimize the risk of exploitation. As a temporary workaround, avoid using the id parameter in this action until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpizabi