LimeSurvey Remote File Include and Directory Traversal Vulnerabilities
BID:54167
Info
LimeSurvey Remote File Include and Directory Traversal Vulnerabilities
| Bugtraq ID: | 54167 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2012 12:00AM |
| Updated: | Jun 22 2012 12:00AM |
| Credit: | dun |
| Vulnerable: |
LimeSurvey LimeSurvey 2.00+ build 131031 |
| Not Vulnerable: | |
Discussion
LimeSurvey Remote File Include and Directory Traversal Vulnerabilities
LimeSurvey is prone to a remote file-include vulnerability and a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to obtain sensitive information and execute malicious code within the context of the web server process. This may aid in further attacks.
LimeSurvey 1.92+ build120620 is vulnerable; other versions may also be affected.
LimeSurvey is prone to a remote file-include vulnerability and a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A successful exploit may allow an attacker to obtain sensitive information and execute malicious code within the context of the web server process. This may aid in further attacks.
LimeSurvey 1.92+ build120620 is vulnerable; other versions may also be affected.