Invision Gallery Index.PHP Directory Traversal Vulnerability
BID:20328
Info
Invision Gallery Index.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 20328 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2006 12:00AM |
| Updated: | Oct 04 2006 03:35PM |
| Credit: | _1nf3ct0r_ is credited with the discovery of this vulnerability. |
| Vulnerable: |
Invision Power Services Invision Gallery 2.0.7 Invision Power Services Invision Gallery 2.0.6 Invision Power Services Invision Gallery 2.0.3 Invision Power Services Invision Gallery 1.3.1 Invision Power Services Invision Gallery 1.3 Invision Power Services Invision Gallery 1.0.1 |
| Not Vulnerable: | |
Discussion
Invision Gallery Index.PHP Directory Traversal Vulnerability
Invision Gallery is prone to a directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Invision Gallery is prone to a directory-traversal vulnerability because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid attackers in further attacks.
Exploit / POC
Invision Gallery Index.PHP Directory Traversal Vulnerability
Attackers can exploit this issue via a web client.
The following exploit is available:
Attackers can exploit this issue via a web client.
The following exploit is available:
Solution / Fix
Invision Gallery Index.PHP Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Invision Gallery Index.PHP Directory Traversal Vulnerability
References:
References: