PT-2016-3689 · Swim Team · Swim Team

Ethicalhack3R

·

Published

2016-01-12

·

Updated

2016-11-28

·

CVE-2015-5471

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Swim Team plugin version 1.44.10777
Description The issue allows remote attackers to read arbitrary files via a full pathname in the file parameter in the include/user/download.php file.
Recommendations For Swim Team plugin version 1.44.10777, consider restricting access to the include/user/download.php file until a patch is available. Avoid using the file parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5471

Affected Products

Swim Team