PT-2011-2864 · Focalmedia.Net · Focalmedia.Net Quick Polls

Mark Stanislav

·

Published

2011-03-09

·

Updated

2018-10-09

·

CVE-2011-1099

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions FocalMedia.Net Quick Polls versions prior to 1.0.2
Description The issue allows remote attackers to read or delete arbitrary files due to directory traversal vulnerabilities. This can be achieved by using a .. (dot dot) in the p parameter in either a preview or delete action to "index.php".
Recommendations For versions prior to 1.0.2, update to version 1.0.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "index.php" file or disabling the preview and delete actions until a patch is available. Avoid using the p parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1099

Affected Products

Focalmedia.Net Quick Polls