vendor:
Glype Proxy
by:
Securify
7,5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Glype Proxy
Affected Version From: 1.4.9
Affected Version To: 1.4.9
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Glype proxy cookie jar path traversal allows code execution
A path traversal vulnerability has been identified in the Glype web-based proxy that allows an attacker to run arbitrary PHP code on the server or to remove critical files from the filesystem. This only affects servers that are configured to store Glype cookies locally, disable PHP display_errors, and allow the webserver process to write to the filesystem (document root).
Mitigation:
Glype was informed and a fixed version (1.4.10) is now available at www.glype.com