vendor:
sflog
by:
muuratsalo
7.5
CVSS
HIGH
Remote File Disclosure
200
CWE
Product Name: sflog
Affected Version From: 0.96
Affected Version To: 0.96
Patch Exists: Yes
Related CWE: N/A
CPE: a:sflog:sflog:0.96
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
sflog! 0.96 remote file disclosure vulnerabilities
Sflog! 0.96 is vulnerable to remote file disclosure. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable server. The request should contain a malicious URL with the ‘blog’ and ‘permalink’ parameters set to ‘../../../../../../../../../../etc/passwd’. This will allow the attacker to view the contents of the ‘/etc/passwd’ file.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of sflog! 0.96.