CVE-2006-2747

Properties

Published:
31.05.2006
Updated:
17.10.2006
Patch available:
Severity:
Medium
CVSS vector:
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
Product:
Fredi Bach: PhpMyDesktop|arcade

Vulnerability description

Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.

References:

BUGTRAQ: http://www.securityfocus.com/archive/1/archive/1/435365/100/0/threaded
FRSIRT: http://www.frsirt.com/english/advisories/2006/2065
SECTRACK: http://securitytracker.com/id?1016180
SECUNIA: http://secunia.com/advisories/20373