|
|
Xrousse Beryo "chemin" Parameter Handling Arbitrary File Download Vulnerability
|
A vulnerability has been identified in Xrousse Beryo, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is due to an input validation error in the "downloadpic.php" script that does not validate the "chemin" parameter before being passed as an argument to a "readfile()" call, which could be exploited by attackers to download arbitrary files from a vulnerable server.
Xrousse Beryo version 2.4 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/1296
Vulnerability reported by GolD_M
2007-04-09 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|