Description
Navigate CMS 2.8.5 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by injecting directory traversal sequences in the id parameter. Attackers can send GET requests to navigate_download.php with path traversal payloads ../../../cfg/globals.php to access sensitive configuration files and system files outside the intended directory.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Ihsan Sencan
References
www.exploit-db.com/exploits/45615 (ExploitDB-45615)
www.navigatecms.com/ (Official Product Homepage)
master.dl.sourceforge.net/...eleases/navigate-2.8.5r1355.zip (Product Reference)
www.vulncheck.com/...ath-traversal-via-navigate-download-php (VulnCheck Advisory: Navigate CMS 2.8.5 Path Traversal via navigate_download.php)