vendor:
FD Script
by:
Unknown
4.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: FD Script
Affected Version From: 1.32
Affected Version To: 1.32
Patch Exists: NO
Related CWE:
CPE: a:fd_script:fd_script:1.32
Platforms Tested:
Unknown
FD Script Information Disclosure Vulnerability
The FD Script application fails to properly sanitize user-supplied input, which can be exploited by an attacker to retrieve arbitrary files from the vulnerable system. This vulnerability exists in FD Script 1.32 and prior versions. By sending a specially crafted request to the 'download.php' script with a manipulated 'fname' parameter, an attacker can retrieve sensitive information from the targeted system, potentially aiding in further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user-supplied input before processing it within the application. Additionally, restricting access to sensitive files and directories can help prevent unauthorized retrieval of information.