Edior CMS 'search.php' Directory Traversal Vulnerability
BID:28242
Info
Edior CMS 'search.php' Directory Traversal Vulnerability
| Bugtraq ID: | 28242 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1352 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Shennan Wang is credited with the discovery of this vulnerability. |
| Vulnerable: |
Hangzhou Network Technology Development Edior CMS 3.0 |
| Not Vulnerable: | |
Discussion
Edior CMS 'search.php' Directory Traversal Vulnerability
Edior CMS is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the application's document root directory. This can expose sensitive information that could help the attacker launch further attacks.
Edior CMS 3.0 is vulnerable; other versions may also be affected.
Edior CMS is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue allows an attacker to access arbitrary files outside of the application's document root directory. This can expose sensitive information that could help the attacker launch further attacks.
Edior CMS 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Edior CMS 'search.php' Directory Traversal Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Edior CMS 'search.php' Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Edior CMS 'search.php' Directory Traversal Vulnerability
References:
References:
- Edior CMS Homepage (Hangzhou Network Technology Development)
- Directory traversal in EdiorCMS V3.0 ([email protected])