imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists folders and their permissions.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/0570 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/424745/30/0/threaded | mailing list exploit vendor advisory |
http://secunia.com/advisories/18802 | exploit third party advisory vendor advisory |
http://www.securityfocus.com/bid/16594 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24641 | vdb entry |