Doufox
cpe:2.3:a:doufox:doufox:*:*:*:*:*:*:*
- 0.1
- 0.2.0
A critical path traversal vulnerability has been identified in Doufox versions through 0.2.0. The issue arises in the file listing functionality accessed via the '/?s=doudou&c=file&a=list' URL. Manipulating the 'dir' argument allows attackers to traverse directories and access files outside the intended directory structure. This vulnerability can be exploited remotely, but requires authentication.
Exploitation of this vulnerability allows for arbitrary file modifications and access to any file on the server, potentially leading to unauthorized data exposure or manipulation.
To reproduce this vulnerability, log into the application and navigate to the file listing feature. Once there, manipulate the 'dir' parameter to include directory traversal sequences, such as '../', to access restricted files. Authenticated users can exploit this vulnerability to read, modify, download, or delete files on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.