CVE-2008-4319

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libra_file_manager:php_filemanager:1.05:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.08:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:*:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.17:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.00:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.03:*:*:*:*:*:*:*

Information

Published : 2008-09-29 12:25

Updated : 2017-09-28 18:32


NVD link : CVE-2008-4319

Mitre link : CVE-2008-4319


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

libra_file_manager

  • php_filemanager