// For flags

CVE-2008-1606

Elastic Path 4.1 - '/manager/FileManager.jsp?dir' Traversal Arbitrary Directory Listing

Severity Score

6.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.

Múltiples vulnerabilidades de Salto de Directorio en Elastic Path (EP) 4.1 y 4.1.1, permiten a atacantes remotos (1) descargar archivos de su elección mediante un .. (punto punto) en el parámetro file de manager/getImportFileRedirect.jsp, (2) subir archivos de su elección mediante un “..\” (punto punto barra invertida) en el parámetro file de importData.jsp y (3) listar contenidos de directorio mediante un .. (punto punto) en el parámetro dir de manager/fileManager.jsp.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-20 First Exploit
  • 2008-04-01 CVE Reserved
  • 2008-04-01 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-11-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Elastic Path
Search vendor "Elastic Path"
Elastic Path
Search vendor "Elastic Path" for product "Elastic Path"
4.1
Search vendor "Elastic Path" for product "Elastic Path" and version "4.1"
-
Affected
Elastic Path
Search vendor "Elastic Path"
Elastic Path
Search vendor "Elastic Path" for product "Elastic Path"
4.1.1
Search vendor "Elastic Path" for product "Elastic Path" and version "4.1.1"
-
Affected