ffileman 'ffileman.cgi' Directory Traversal Vulnerability
BID:47749
Info
ffileman 'ffileman.cgi' Directory Traversal Vulnerability
| Bugtraq ID: | 47749 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2011 12:00AM |
| Updated: | May 09 2011 12:00AM |
| Credit: | Raffaele Forte |
| Vulnerable: |
ffileman ffileman 7.0 |
| Not Vulnerable: |
ffileman ffileman 8.0 |
Discussion
ffileman 'ffileman.cgi' Directory Traversal Vulnerability
ffileman is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
ffileman 7.0 is vulnerable; other versions may also be affected.
ffileman is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
ffileman 7.0 is vulnerable; other versions may also be affected.
Exploit / POC
ffileman 'ffileman.cgi' Directory Traversal Vulnerability
An attacker can exploit this issue with a web browser.
The following example URI is available:
http://www.example.com/cgi-bin/ffileman.cgi?direkt=../../../../../../../../&kullanici=[username]&sifre=[password]&dizin_git=Vai%20alla%20Directory
An attacker can exploit this issue with a web browser.
The following example URI is available:
http://www.example.com/cgi-bin/ffileman.cgi?direkt=../../../../../../../../&kullanici=[username]&sifre=[password]&dizin_git=Vai%20alla%20Directory
Solution / Fix
ffileman 'ffileman.cgi' Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.