Project

General

Profile

Actions

Bug #5203

closed

Directory transversal in Configuration History

Added by Fernando Munoz over 8 years ago. Updated over 8 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Web Interface
Target version:
Start date:
09/24/2015
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:
All

Description

getcfg parameter doesn't filter chars with as .. or / this way an admin can retrieve other XML files from the system.

- https://localhost:9090/diag_confbak.php?getcfg=../../../../../../../../cf/conf/config

I don't think it's critical since the admin could still download the current config or any other files from other places or SSH, but still you may want to get it fixed.

Actions

Also available in: Atom PDF