vendor:
Picture Manager
by:
ByALBAYX
7.5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Picture Manager
Affected Version From: 0.11
Affected Version To: 0.11
Patch Exists: NO
Related CWE: N/A
CPE: skyportal.net/mod_gallery_0_11.zip
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SkyPortal Picture Manager v0.11
SkyPortal Picture Manager v0.11 is prone to a path-traversal vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this issue to access sensitive files outside of the web root, potentially resulting in the disclosure of sensitive information. This issue affects the following scripts: admin_pic_picedit.asp, admin_pic_browse.asp, admin_pic_showbadlink.asp, and admin_pic_picedit.asp?status=delete.
Mitigation:
User input should be properly sanitized and validated.