header-logo
Suggest Exploit
vendor:
KPF File Sharing Utility
by:
SecurityFocus
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: KPF File Sharing Utility
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2002

KPF File Sharing Utility Vulnerability

It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root. The ability to read files outside of the shared root directory would be dependent upon the privileges of the kpf process.

Mitigation:

Restrict access to the kpf process and ensure that the shared directory root is properly configured.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/5951/info

A vulnerability has been discovered in the kpf file sharing utility. KDE is available for the Linux operating system.

It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root. The ability to read files outside of the shared root directory would be dependent upon the privileges of the kpf process. 

http://127.0.0.1:8001/?icon=/usr/local/kde/share/icons/hicolor/32x32/mimetypes/image.png