Ajax File and Image Manager 'search_folder' Parameter Directory Traversal Vulnerability
BID:66071
Info
Ajax File and Image Manager 'search_folder' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 66071 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2014 12:00AM |
| Updated: | Mar 07 2014 12:00AM |
| Credit: | Eduardo Alves |
| Vulnerable: |
PHPLETTER.COM Ajax File and Image Manager 0 |
| Not Vulnerable: | |
Discussion
Ajax File and Image Manager 'search_folder' Parameter Directory Traversal Vulnerability
Ajax File and Image Manager is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker can use directory-traversal strings to retrieve arbitrary files in the context of the affected application.
Ajax File and Image Manager is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
A remote attacker can use directory-traversal strings to retrieve arbitrary files in the context of the affected application.
Exploit / POC
Ajax File and Image Manager 'search_folder' Parameter Directory Traversal Vulnerability
Attackers can use standard, readily available tools to exploit this issue.
Attackers can use standard, readily available tools to exploit this issue.
References
Ajax File and Image Manager 'search_folder' Parameter Directory Traversal Vulnerability
References:
References:
- Ajax File and Image Manager Homepage (phpletter)