Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:25237
HistoryDec 06, 2010 - 12:00 a.m.

Local file view in Etomite

2010-12-0600:00:00
vulners.com
25

Vulnerability ID: HTB22712
Reference: http://www.htbridge.ch/advisory/local_file_view_in_etomite.html
Product: Etomite
Vendor: http://www.etomite.org/ ( http://www.etomite.org/ )
Vulnerable Version: 1.1
Vendor Notification: 18 November 2010
Vulnerability Type:
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: High
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)

Vulnerability Details:
The vulnerability exists due to failure in the "/manager/actions/static/document_data.static.action.php" script to properly sanitize user-supplied input in "id" variable.
A remote user can view any local file.

http://etomite/manager/actions/static/document_data.static.action.php?id=/../../../../includes/config.inc.php%00