Pheap.Edit.PHP.Filename.Parameter

NamePheap.Edit.PHP.Filename.Parameter.Directory.Traversal
Release DateJan 26, 2010
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against a directory-traversal vulnerability in the Pheap CMS web application.

A vulnerability has been reported in the Pheap CMS web application that may allow an attacker to read arbitrary files on a vulnerable system. This is possible because the user input filters fail to properly sanitize the "filename" parameter value. An attacker may read and modify arbitrary files by sending a crafted HTTP request.
Affected ProductsPheap Pheap 2.0
Pheap Pheap 1.3
Pheap Pheap 1.1
Pheap Pheap 1.0
Recommended ActionsCurrently we are not aware of any officially supplied patch for this issue.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2007-1140
Reference/shttp://www.securityfocus.com/bid/22670 (BugTraq)
http://www.securityfocus.com/archive/1/460920
Reference: VID-18061