vendor:
EasyWeb FileManager
by:
Unknown
5.5
CVSS
MEDIUM
Directory Traversal
22
CWE
Product Name: EasyWeb FileManager
Affected Version From: EasyWeb FileManager 1.0 RC-1
Affected Version To: EasyWeb FileManager 1.0 RC-1
Patch Exists: Unknown
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
EasyWeb Directory Traversal Vulnerability
EasyWeb is prone to a directory traversal vulnerability. This issue presents itself due to insufficient sanitization of user-supplied data. The issue occurs if a remote attacker sends a request to the 'ew_filemanager' script for a file containing directory traversal character sequences to the application.
Mitigation:
Unknown