PHPMyExplorer Arbitrary File Disclosure Vulnerability
BID:3266
Info
PHPMyExplorer Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 3266 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on August 29th, 2001 by Ben Ford <[email protected]>. |
| Vulnerable: |
PHPMyExplorer PHPMyExplorer MultiUser 1.0 PHPMyExplorer PHPMyExplorer Classic 1.2 PHPMyExplorer PHPMyExplorer Classic 1.1.5 PHPMyExplorer PHPMyExplorer Classic 1.1.4 PHPMyExplorer PHPMyExplorer Classic 1.1.3 PHPMyExplorer PHPMyExplorer Classic 1.1.1 PHPMyExplorer PHPMyExplorer Classic 1.1 .0 PHPMyExplorer PHPMyExplorer Classic 1.0 |
| Not Vulnerable: |
PHPMyExplorer PHPMyExplorer Classic 1.2.1 |
Discussion
PHPMyExplorer Arbitrary File Disclosure Vulnerability
PHPMyExplorer is a free application that provides a web user interface for managing web content on a host. It works with Apache for Microsoft Windows systems and also on Linux platforms.
An input validation problem exists with PHPMyExplorer. It is possible for a user to browse the filesystem of the host using specially crafted a URL using variations of '../' sequences to break out of wwwroot.
As a result the attacker will be able to display arbitrary web-readable files, potentially disclosing sensitive information about the host.
PHPMyExplorer is a free application that provides a web user interface for managing web content on a host. It works with Apache for Microsoft Windows systems and also on Linux platforms.
An input validation problem exists with PHPMyExplorer. It is possible for a user to browse the filesystem of the host using specially crafted a URL using variations of '../' sequences to break out of wwwroot.
As a result the attacker will be able to display arbitrary web-readable files, potentially disclosing sensitive information about the host.
Exploit / POC
PHPMyExplorer Arbitrary File Disclosure Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.
References
PHPMyExplorer Arbitrary File Disclosure Vulnerability
References:
References:
- PHPMyExplorer Homepage (PhpMyExplorer)