Beveiligingsadvies

CVE-2008-6592

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2009-04-03 18:00:00
Laatst bijgewerkt 2024-08-07 11:34:47
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).