Doufox Path Traversal Vulnerability in File Listing Functionality

Vulnerability

A critical path traversal vulnerability has been identified in Doufox versions through 0.2.0. The issue arises in the file listing functionality accessed via the '/?s=doudou&c=file&a=list' URL. Manipulating the 'dir' argument allows attackers to traverse directories and access files outside the intended directory structure. This vulnerability can be exploited remotely, but requires authentication.

Impact

Exploitation of this vulnerability allows for arbitrary file modifications and access to any file on the server, potentially leading to unauthorized data exposure or manipulation.

Reproduction

To reproduce this vulnerability, log into the application and navigate to the file listing feature. Once there, manipulate the 'dir' parameter to include directory traversal sequences, such as '../', to access restricted files. Authenticated users can exploit this vulnerability to read, modify, download, or delete files on the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.