|
ImageFolio Directory Traversal and Default Password
|
|
Secunia Advisory:
|
SA8964
|
|
|
Release Date:
|
2003-06-09
|
|
Popularity:
|
5,008 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of sensitive information
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | ImageFolio 3.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: A vulnerability has been identified in ImageFolio allowing users to conduct directory traversal.
The problem is that the remove function doesn't verify user input allowing users to supply character sequences like "../". This allows malicious users to view contents of directories and remove files and directories which the process got write access to.
Further ImageFolio comes with a default account:
Username: Admin
Password: ImageFolio
Solution: Make sure that you change the default password. Only allow access to the admin functions to users you trust. To add further security to the admin area it could be protected with .htaccess or similar.
The vendor have suggested some changes to improve security:
http://www.imagefolio.com/ubb/Forum25/HTML/000019.html
Provided and/or discovered by: Paul Craig
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|