PT-2010-3350 · Siestta · Siestta
Published
2010-05-04
·
Updated
2017-08-17
·
CVE-2010-1710
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Siestta version 2.0
Description
A directory traversal issue exists in the login.php file of Siestta, allowing remote attackers to include and execute arbitrary local files. This is possible when the register globals setting is enabled. The issue can be exploited by using a .. (dot dot) in the
idioma parameter of the vulnerable endpoint.Recommendations
For Siestta version 2.0, consider disabling the register globals setting to prevent exploitation. As a temporary workaround, restrict access to the login.php file until a patch is available. Avoid using the
idioma parameter in the affected endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siestta