4
CVSSv2

CVE-2011-4831

Published: 15/12/2011 Updated: 09/02/2012
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.

Vulnerable Product Search on Vulmon Subscribe to Product

david azoulay web file browser 0.4b14

Exploits

Exploit Title: [Web File Browser 04b14 File Download Vulnerability] # Date: [2011/11/03] # Author: [Sangyun YOO] # Email: yoosy0302 at naver dot com # Software Link: [ downloadssourceforgenet/project/webfilebrowser/webfilebrowser/04b14/webfilebrowser-04b14zip ] # Version: [Web File Browser 04b14] # Tested on: [Windows 7 Starter K] --- ...