Vulnerability Description
phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codnloc | Phptransformer | 2016.9 |
Related Weaknesses (CWE)
References
- http://phptransformer.com/Product
- https://netcologne.dl.sourceforge.net/project/phptransformer/Version%202016.9/reBroken Link
- https://www.exploit-db.com/exploits/46192ExploitVDB Entry
- https://www.vulncheck.com/advisories/phptransformer-directory-traversal-via-jqueThird Party Advisory
FAQ
What is CVE-2019-25579?
CVE-2019-25579 is a vulnerability with a CVSS score of 7.5 (HIGH). phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to th...
How severe is CVE-2019-25579?
CVE-2019-25579 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25579?
Check the references section above for vendor advisories and patch information. Affected products include: Codnloc Phptransformer.