CVE-2008-4319

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libra_file_manager:php_filemanager:*:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.00:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.03:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.05:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.08:*:*:*:*:*:*:*
cpe:2.3:a:libra_file_manager:php_filemanager:1.17:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-09-29 19:25

Updated : 2023-12-10 10:51


NVD link : CVE-2008-4319

Mitre link : CVE-2008-4319

CVE.ORG link : CVE-2008-4319


JSON object : View

Products Affected

libra_file_manager

  • php_filemanager
CWE
CWE-287

Improper Authentication