MKPortal Index.PHP Directory Traversal Vulnerability
BID:18707
CVE-2006-3554 |Info
MKPortal Index.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 18707 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2006 12:00AM |
| Updated: | Jun 28 2006 11:09PM |
| Credit: | rUnViRuS is credited with the discovery of this vulnerability. |
| Vulnerable: |
MKPortal MKPortal 1.0.1 Final |
| Not Vulnerable: | |
Discussion
MKPortal Index.PHP Directory Traversal Vulnerability
MKPortal is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
This issue affects version 1.0.1 Final; other versions may also be vulnerable.
MKPortal is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
This issue affects version 1.0.1 Final; other versions may also be vulnerable.
Exploit / POC
MKPortal Index.PHP Directory Traversal Vulnerability
This vulnerability may be exploited via a web client.
The following exploit is available:
This vulnerability may be exploited via a web client.
The following exploit is available:
Solution / Fix
MKPortal Index.PHP Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].