vendor:
phpTransformer
by:
Ihsan Sencan
7.5
CVSS
HIGH
Directory Traversal
22
CWE
Product Name: phpTransformer
Affected Version From: 2016.9
Affected Version To: 2016.9
Patch Exists: YES
Related CWE: N/A
CPE: a:phptransformer:phptransformer:2016.9
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2019
phpTransformer 2016.9 – Directory Traversal
A directory traversal vulnerability exists in phpTransformer 2016.9, which allows an attacker to read arbitrary files on the server. The vulnerability exists due to insufficient validation of user-supplied input in the 'path' parameter of the 'index.php' script. An attacker can send a specially crafted HTTP request containing directory traversal sequences (e.g. '../') to read arbitrary files on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of phpTransformer.