CVE-2008-4319 Information

Description

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication and read arbitrary files modify arbitrary files and list arbitrary directories by inserting certain user and isadmin parameters in the query string.

Reference

http://www.securityfocus.com/archive/1/496742 http://www.securityfocus.com/bid/31415 https://exchange.xforce.ibmcloud.com/vulnerabilities/45423 https://www.exploit-db.com/exploits/6567

Share on: