header-logo
Suggest Exploit
vendor:
EasyWeb FileManager
by:
Unknown
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: EasyWeb FileManager
Affected Version From: EasyWeb FileManager 1.0 RC-1
Affected Version To: EasyWeb FileManager 1.0 RC-1
Patch Exists: Unknown
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Unknown
Unknown

EasyWeb Directory Traversal Vulnerability

EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.

Mitigation:

Unknown
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/10792/info

EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.

EasyWeb FileManager 1.0 RC-1 is prone to this issue.

Update: Conflicting reports suggest that this issue may not be a vulnerability as access to various files can be limited by an EasyWeb administrator. An attacker with valid account credentials may only be able to carry out an attack. This BID will be updated as more information becomes available.

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc

/index.php?module=ew_filemanager&type=admin&func=manager&pathext=../../../etc/&view=passwd