PT-2010-1692 · Php Community · Phpcommunity 2
Drosophila
+1
·
Published
2010-06-11
·
Updated
2018-10-10
·
CVE-2009-4886
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpCommunity 2 version 2.1.8
Description
The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This is achieved by including a .. (dot dot) in the
file parameter to "module/admin/files/show file.php" and the path parameter to "module/admin/files/show source.php".Recommendations
For phpCommunity 2 version 2.1.8, consider restricting access to the "module/admin/files/show file.php" and "module/admin/files/show source.php" until a patch is available. Avoid using the
file and path parameters in the affected API endpoints until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpcommunity 2