ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
BID:38651
Info
ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
| Bugtraq ID: | 38651 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 10 2010 12:00AM |
| Updated: | Mar 10 2010 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
ImgBrowz0r ImgBrowz0r 0.3.5 |
| Not Vulnerable: |
ImgBrowz0r ImgBrowz0r 0.3.6 |
Discussion
ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
ImgBrowz0r is prone to a remote directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
ImgBrowz0r 0.3.5 is vulnerable; other versions may also be affected.
ImgBrowz0r is prone to a remote directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
ImgBrowz0r 0.3.5 is vulnerable; other versions may also be affected.
Exploit / POC
ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
ImgBrowz0r 'imgbrowz0r::init()' Function Remote Directory Traversal Vulnerability
References:
References:
- ImgBrowz0r Homepage (ImgBrowz0r)
- ImgBrowz0r Changelog (ImgBrowz0r)