| Anonymous | Login | Signup for a new account | 2013.05.21 14:34 CEST |
| Main | My View | View Issues | Change Log | Roadmap | Docs |
| Viewing Issue Advanced Details [ Jump to Notes ] | [ Issue History ] [ Print ] | ||||||
| ID | Category | Severity | Reproducibility | Date Submitted | Last Update | ||
| 0002843 | [Piwigo] security | minor | unable to reproduce | 2013.02.11 22:48 | 2013.02.19 22:36 | ||
| Reporter | plg | View Status | public | ||||
| Assigned To | plg | ||||||
| Priority | normal | Resolution | fixed | Platform | |||
| Status | closed | OS | |||||
| Projection | none | OS Version | |||||
| ETA | none | Fixed in Version | 2.4.7 | Product Version | 2.4.6 | ||
| Target Version | 2.4.7 | Product Build | |||||
| Summary | 0002843: [install.php on Windows] improved security on temporary config file download | ||||||
| Description |
Add user input check on $_GET['dl'] I was not able to reproduce any security failure on Linux but let's add a filter to increase security. |
||||||
| Steps To Reproduce | if Piwigo is installed on Windows, install.php.dl=../../comments.php | ||||||
| Additional Information |
Originally reported by htbridge https://www.htbridge.com/advisory/HTB23144 [^] Secondly reported by Gjoko Krstic http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5127.php [^] |
||||||
| Tags | No tags attached. | ||||||
| browser | any | ||||||
| Database engine and version | |||||||
| PHP version | |||||||
| Web server | Apache 1.3.x | ||||||
| Attached Files | |||||||
|
|
|||||||
Notes |
|
|
(0006843) plg (manager) 2013.02.11 22:50 edited on: 2013.02.11 22:50 |
[Subversion] r20706 on branch 2.4 |
|
(0006844) svn (reporter) 2013.02.11 22:52 |
[Subversion] r20707 by plg on trunk -----[Subversion commit log]---------------------------------------------------- merge r20706 from branch 2.4 to trunk bug 2843: filter $_GET['dl'], it must be a md5sum-like string and nothing else |
| Mantis 1.1.6[^] Copyright © 2000 - 2008 Mantis Group Contact |