Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.
References
Configurations
History
20 Nov 2024, 23:52
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.html - Vendor Advisory | |
References | () http://secunia.com/advisories/11640 - Patch, Vendor Advisory | |
References | () http://securitytracker.com/id?1010190 - Patch | |
References | () http://www.phpmyfaq.de/advisory_2004-05-18.php - Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/363636 - | |
References | () http://www.securityfocus.com/bid/10377 - Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/16223 - |
Information
Published : 2004-12-31 05:00
Updated : 2024-11-20 23:52
NVD link : CVE-2004-2256
Mitre link : CVE-2004-2256
CVE.ORG link : CVE-2004-2256
JSON object : View
Products Affected
phpmyfaq
- phpmyfaq
CWE