fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-09-29 12:25
Updated : 2017-09-28 18:32
NVD link : CVE-2008-4319
Mitre link : CVE-2008-4319
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
libra_file_manager
- php_filemanager