Page 7 of 32 results (0.007 seconds)

CVSS: 6.4EPSS: 0%CPEs: 6EXPL: 3

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string. El módulo fileadmin.php en Libra File Manager (también conocido como Libra PHP File Manager) v1.18 y anteriores permite a atacantes remotos evitar la autenticación, leer ficheros arbitrarios, modificar ficheros arbitrarios y listar el contenido de directorios arbitrarios, al insertar ciertos parámetros "user" e "isadmin" en la cadena de consulta. • https://www.exploit-db.com/exploits/6567 http://www.securityfocus.com/archive/1/496742 http://www.securityfocus.com/bid/31415 https://exchange.xforce.ibmcloud.com/vulnerabilities/45423 • CWE-287: Improper Authentication •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks. • http://marc.info/?l=bugtraq&m=111868578006615&w=2 http://www.osvdb.org/20257 •