Описание
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | ignored | end of life |
| devel | DNE | pulled 2010-07-27 |
| hardy | ignored | end of life |
| jaunty | released | 1:0.9.16.012+dfsg-8+lenny2build0.9.04.1 |
| karmic | released | 1:0.9.16.012+dfsg-8+lenny2build0.9.10.1 |
| lucid | ignored | end of life |
| maverick | DNE | pulled 2010-07-27 |
| natty | DNE | pulled 2010-07-27 |
| oneiric | DNE | pulled 2010-07-27 |
| precise | DNE | pulled 2010-07-27 |
Показывать по
Ссылки на источники
6.8 Medium
CVSS2
Связанные уязвимости
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) ...
Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
6.8 Medium
CVSS2