vendor:
iManager Plugin
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Remote Arbitrary File Deletion
22
CWE
Product Name: iManager Plugin
Affected Version From: <= 1.2.8 Build 02012008
Affected Version To: <= 1.2.8 Build 02012008
Patch Exists: YES
Related CWE: N/A
CPE: a:net4visions.com:imanager_plugin:1.2.8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN), Apache 2.2.14 (Win32), PHP 5.3.1, MySQL 5.1.41
2011
iManager Plugin v1.2.8 (d) Remote Arbitrary File Deletion Vulnerability
Input passed to the 'd' parameter in /scripts/phpCrop/crop.php is not properly sanitised before being used to delete files. This can be exploited to delete files with the permissions of the web server via directory traversal sequences passed within the 'd' parameter.
Mitigation:
Input validation should be performed to ensure that untrusted input is not used to delete files.