vendor:
TuMusika Evolution
by:
Unknown
7.5
CVSS
HIGH
Remote File Disclosure
22
CWE
Product Name: TuMusika Evolution
Affected Version From: 1.7R5
Affected Version To: 1.7R5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
TuMusika Evolution 1.7R5 Remote File Disclosure Vulnerability
The vulnerability allows an attacker to disclose files on the server by exploiting a flaw in the TuMusika Evolution 1.7R5 script. By manipulating the 'uri' parameter in the sc_download.php script, an attacker can traverse the file system and access sensitive files. The exploit example provided demonstrates accessing the /etc/passwd file.
Mitigation:
The vendor should release a patch to fix the vulnerability. In the meantime, users are advised to restrict access to the sc_download.php script and sanitize user input to prevent directory traversal attacks.