vendor:
CMS
by:
KiNgOfThEwOrLd
5.5
CVSS
MEDIUM
Credentials Disclosure
CWE
Product Name: CMS
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Eurologon CMS Db credentials disclosure / files download
The download module does not correctly check the file parameter, allowing for directory traversal and the ability to download all files hosted in the target web space.
Mitigation:
The vendor should update the download module to properly validate the file parameter and prevent directory traversal.