CVE-2006-2747

Properties

Published:
31.05.2006
Updated:
22.10.2018
Patch available:
Severity:
Medium
CVSS vector:
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
Product:
fredi_bach: phpmydesktop_arcade

Vulnerability description

Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.

References:

SREASON: http://securityreason.com/securityalert/1009
SECTRACK: http://securitytracker.com/id?1016180
BUGTRAQ: http://www.securityfocus.com/archive/1/435365/100/0/threaded
BID: http://www.securityfocus.com/bid/18185
VUPEN: http://www.vupen.com/english/advisories/2006/2065
XF: https://exchange.xforce.ibmcloud.com/vulnerabilities/26724