Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2005-4600

Опубликовано: 31 дек. 2005
Источник: debian
EPSS Средний

Описание

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
knowledgerootnot-affectedpackage
moodlenot-affectedpackage
wordpressfixed2.5.1-3package
wordpressnot-affectedetchpackage

Примечания

  • this was possibly fixed before 2.5.1 in wordpress but since 2.5.1-3 wordpress

  • uses the system copy of tinymce and the exact fixed version is not

  • really determinably anymore

EPSS

Процентиль: 95%
0.17865
Средний

Связанные уязвимости

nvd
почти 20 лет назад

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

github
больше 3 лет назад

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

EPSS

Процентиль: 95%
0.17865
Средний