Описание
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2005-2813
- http://seclists.org/lists/bugtraq/2005/Aug/0440.html
- http://secunia.com/advisories/16650
- http://securitytracker.com/id?1014824
- http://securitytracker.com/id?1015339
- http://www.securityfocus.com/archive/1/419107/100/0/threaded
- http://www.securityfocus.com/bid/14702
- http://www.securityfocus.com/bid/15796
EPSS
Процентиль: 91%
0.07078
Низкий
CVE ID
Связанные уязвимости
nvd
больше 20 лет назад
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.
EPSS
Процентиль: 91%
0.07078
Низкий