NX5Linkx Link.PHP Directory Traversal Vulnerability
BID:20008
CVE-2006-4503 |Info
NX5Linkx Link.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 20008 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4503 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2006 12:00AM |
| Updated: | Sep 14 2006 06:58PM |
| Credit: | Aliaksandr Hartsuyeu is credited with the discovery of this vulnerability. |
| Vulnerable: |
NX5 NX5Linkx 1.0 |
| Not Vulnerable: | |
Discussion
NX5Linkx Link.PHP Directory Traversal Vulnerability
NX5Linkx is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
NX5Linkx is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks.
Exploit / POC
NX5Linkx Link.PHP Directory Traversal Vulnerability
Attackers can exploit this vulnerability with a standard web browser.
Attackers can exploit this vulnerability with a standard web browser.
Solution / Fix
NX5Linkx Link.PHP Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied fixes for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied fixes for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
NX5Linkx Link.PHP Directory Traversal Vulnerability
References:
References:
- NX5 Homepage (NX5)
- [eVuln] NX5Linkx Multiple Vulnerabilities (Alex)