fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/archive/1/496742 - Exploit | |
References | () http://www.securityfocus.com/bid/31415 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/45423 - | |
References | () https://www.exploit-db.com/exploits/6567 - |
Information
Published : 2008-09-29 19:25
Updated : 2024-11-21 00:51
NVD link : CVE-2008-4319
Mitre link : CVE-2008-4319
CVE.ORG link : CVE-2008-4319
JSON object : View
Products Affected
libra_file_manager
- php_filemanager
CWE
CWE-287
Improper Authentication