vendor:
ActiveCollab
by:
Jose Carlos de Arriba (DaDe)
N/A
CVSS
N/A
Local File Inclusion / Directory Traversal
22
CWE
Product Name: ActiveCollab
Affected Version From: 2.3.0
Affected Version To: 2.3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:activecollab:activecollab
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
PAINSEC SECURITY RESEARCH GROUP SECURITY ADVISORY 2010-001
ActiveCollab presents a Local File Inclusion / Directory Traversal vulnerability on its “module” parameter, due to an insufficient sanitization on user supplied data. A malicious user could get all the files in the web server, and also get all a shell in the system, in case of being able to write PHP code in any file that could be loaded through the “module” parameter (i.e Apache logs).
Mitigation:
Corrected