vendor:
MiniGal b13
by:
Alfons Luja
5
CVSS
MEDIUM
Source Code Disclosure
22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
CWE
Product Name: MiniGal b13
Affected Version From: MiniGal b13
Affected Version To: MiniGal b13
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
MiniGal b13 Source Code Disclosure
Alfons Luja discovered a vulnerability in MiniGal b13, which can be exploited by malicious people to disclose potentially sensitive information. The vulnerability is caused due to the application not properly sanitizing user-supplied input to the 'list' parameter in 'index.php'. This can be exploited to disclose the source code of arbitrary files via a directory traversal attack.
Mitigation:
No known mitigation was available at the time of disclosure.