Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4319

Опубликовано: 29 сент. 2008
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libra_file_manager:php_filemanager:*:*:*:*:*:*:*:*
Версия до 1.18 (включая)
cpe:2.3:a:libra_file_manager:php_filemanager:1.00:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.03:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.05:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.08:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.17:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03367
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.

EPSS

Процентиль: 87%
0.03367
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287