CVE-2008-4319
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin…
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- libra file manager/php filemanager
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/496742Exploit
- http://www.securityfocus.com/bid/31415Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45423
- https://www.exploit-db.com/exploits/6567
- http://www.securityfocus.com/archive/1/496742Exploit
- http://www.securityfocus.com/bid/31415Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45423
- https://www.exploit-db.com/exploits/6567
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.