vendor:
Collaborative Passwords Manager (cPassMan)
by:
Kaan Kivilcim
5.5
CVSS
MEDIUM
Local file system access
N/A
CWE
Product Name: Collaborative Passwords Manager (cPassMan)
Affected Version From: 1.82
Affected Version To: 1.82
Patch Exists: NO
Related CWE: Not yet assigned
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Independent (PHP)
2011
Sense of Security – Security Advisory – SOS-11-004
A vulnerability has been discovered in the Collaborative Passwords Manager (cPassMan) web application that can be exploited to retrieve files from the local host file system. The input passed to the component 'sources/downloadfile.php' via the 'path' variable allows the retrieval of any file on the local file system that the web server has access to. There is no data validation or authorisation mechanisms present within this component.
Mitigation:
Upgrade to v2.0, v1.x branch no longer updated