Описание
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
Дополнительная информация
Статус:
Important
Дефект:
CWE-73->CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=530255Sahana: Arbitrary files access due improper processing of URLs with null character in the string
7.5 High
CVSS2
Связанные уязвимости
nvd
больше 16 лет назад
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
debian
больше 16 лет назад
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 a ...
github
почти 4 года назад
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
7.5 High
CVSS2