vendor:
sFileManager
by:
Pepelux
8,8
CVSS
HIGH
Local File Inclusion
98
CWE
Product Name: sFileManager
Affected Version From: <= v.24a
Affected Version To: <= v.24a
Patch Exists: YES
Related CWE: N/A
CPE: o:onedotoh:sfilemanager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
sFileManager <= v.24a / Local File Inclusion Vulnerability
sFileManager version <= v.24a is vulnerable to a Local File Inclusion vulnerability. When the user clicks to download a file, two parameters are passed: action and pathext. The pathext parameter is checked for any malicious input, however, the action parameter is not checked and can be used to read any file in the server.
Mitigation:
Upgrade to the latest version of sFileManager.