HomeSecurityCritical vulnerabilities affect PHP file Manager

Critical vulnerabilities affect PHP file Manager

Critical vulnerabilities affect PHP file Manager – PHP File Manager has been affected by several critical vulnerabilities for almost 5 years, according to security Sijmen Ruwhof.

In July 2010, Ruwhof was looking for a web-based file manager to use on his own web server when he stumbled upon PHP File Manager. From that moment on, he discovered that the product had some critical vulnerabilities that could be easily exploited.

"While studying it, I came across some shocking findings which I am listing in my article. This commercial software product contains some critical security vulnerabilities that can be very easily exploited. Furthermore, it even includes a weak security backdoor, thus leaving the web based file manager completely open to attacks," says Mr. Sijmen Ruwhof.

Sijmen Ruwhof tried 3 times to contact the company Revived Wire Media (the owner of PHP file Manager) without success, so he decided to disclose the security issues to the public.

Critical vulnerabilities affect PHP file Manager
Well-known companiessuch as Eneco, Nintendo, Danone, Nestle, Loreal, EON, Siemens, Vattenfall, Oracle, Oxford, Hilton, T-mobile, CBS, UPC, 3M, etc. are exposed to cyber attacks because they use the product in question.

Here are some of the bugs he discovered in the PHP file manager:
• Built-in backdoor, which could be exploited to gain access to the PHP file manager.
• Knowledge of the username that gives access to the software (it is text-based).
• The DB can be downloaded using any web browser.
• Cache that contains sensitive information such as usernames and password hashes.

"Password hashes stored in the user database are unsalted and generated using the deprecated MD5 hash algorithm. Most of these hashes can be readily reverted to their original password using online MD5 reversing services," Ruwhof says in his report.

In addition to these, the software has no password security policy, suffers from cross-site scripting and cross-site request forgery vulnerabilities, is vulnerable to brute-force attacks, and stores PHP session files in the web root.

Five years is a long time, and more than enough to fix all these flaws, although it is uncertain whether Revived Wire Media will fix them in the future because it seems that PHP File Manager has not been upgraded in the last four years.

You can read Ruwhof's full detailed analysis here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS