Описание
Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.
Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2005-1621
- http://cvs.postnuke.com/viewcvs.cgi/Historic_PostNuke_Library/postnuke-devel/html/includes/pnMod.php.diff?r1=1.47&r2=1.48
- http://marc.info/?l=bugtraq&m=111627124301526&w=2
- http://news.postnuke.com/Article2690.html
- http://news.postnuke.com/modules.php?op=modload&name=News&file=article&sid=2691
- http://www.vupen.com/english/advisories/2005/0553
EPSS
Процентиль: 75%
0.00874
Низкий
CVE ID
Связанные уязвимости
nvd
больше 20 лет назад
Directory traversal vulnerability in the pnModFunc function in pnMod.php for PostNuke 0.750 through 0.760rc4 allows remote attackers to read arbitrary files via a .. (dot dot) in the func parameter to index.php.
EPSS
Процентиль: 75%
0.00874
Низкий