EasyWeb 1.0 FileManager Module - Directory Traversal

EDB-ID:

24306




Platform:

PHP

Date:

2004-07-23


source: https://www.securityfocus.com/bid/10792/info

EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.

EasyWeb FileManager 1.0 RC-1 is prone to this issue.

Update: Conflicting reports suggest that this issue may not be a vulnerability as access to various files can be limited by an EasyWeb administrator. An attacker with valid account credentials may only be able to carry out an attack. This BID will be updated as more information becomes available.

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd