PT-2009-2402 · Minigal · Minigal

Alfons Luja

·

Published

2009-08-11

·

Updated

2017-09-29

·

CVE-2008-6933

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: MiniGal version b13
Description: A directory traversal issue in index.php allows remote attackers to read the source code of .php files, and possibly the content of other files, via a .. (dot dot) in the list parameter.
Recommendations: For MiniGal version b13, consider restricting access to the index.php file until a patch is available. As a temporary workaround, avoid using the list parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6933

Affected Products

Minigal