PT-2010-4032 · Linker · Linker Img
Sn!Per.S!Te Hacker
·
Published
2010-06-25
·
Updated
2017-08-17
·
CVE-2010-2456
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linker IMG versions 1.0 and earlier
Description
The issue allows remote attackers to read and execute arbitrary local files. This can be achieved via a URL in the
cook lan cookie parameter, which is associated with the $lan dir variable, or possibly the Sdb type parameter.Recommendations
For versions 1.0 and earlier, consider restricting access to the
index.php file until a fix is available. As a temporary workaround, avoid using the cook lan cookie parameter and the Sdb type parameter in the affected URL.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linker Img