PT-2009-2062 · Unknown+2 · Lightneasy+2

Girex

·

Published

2009-04-03

·

Updated

2018-10-11

·

CVE-2008-6592

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Thumbs-Up version 1.12 LightNEasy "no database" (aka flat) SQLite versions 1.2.2 and earlier
Description The issue allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache dir parameter containing a %00 (encoded null byte).
Recommendations For Thumbs-Up version 1.12, consider restricting access to the thumbsup.php file until a patch is available. For LightNEasy "no database" (aka flat), restrict the use of the image parameter in the affected endpoint to minimize the risk of exploitation. For SQLite versions 1.2.2 and earlier, avoid using the cache dir parameter with encoded null bytes (%00) in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6592

Affected Products

Lightneasy
Sqlite
Thumbs-Up