CVE-2006-0445

index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display the full path of uploader.php. NOTE: this might be the result of a file inclusion vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpclanwebsite:phpclanwebsite:1.23.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:06

Type Values Removed Values Added
References () http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt - Exploit, Vendor Advisory () http://www.h4cky0u.org/advisories/HYSA-2006-002-phpclan.txt - Exploit, Vendor Advisory
References () http://www.osvdb.org/22721 - () http://www.osvdb.org/22721 -
References () http://www.securityfocus.com/archive/1/423145/100/0/threaded - () http://www.securityfocus.com/archive/1/423145/100/0/threaded -
References () http://www.securityfocus.com/bid/16391 - () http://www.securityfocus.com/bid/16391 -

Information

Published : 2006-01-26 22:03

Updated : 2024-11-21 00:06


NVD link : CVE-2006-0445

Mitre link : CVE-2006-0445

CVE.ORG link : CVE-2006-0445


JSON object : View

Products Affected

phpclanwebsite

  • phpclanwebsite