CVE-2004-2256

D

irectory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.

Configurations

Configuration 1 (hide)

cpe:2.3:a:phpmyfaq:phpmyfaq:1.4_alpha1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.html - Vendor Advisory () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.html - Vendor Advisory
References () http://secunia.com/advisories/11640 - Patch, Vendor Advisory () http://secunia.com/advisories/11640 - Patch, Vendor Advisory
References () http://securitytracker.com/id?1010190 - Patch () http://securitytracker.com/id?1010190 - Patch
References () http://www.phpmyfaq.de/advisory_2004-05-18.php - Vendor Advisory () http://www.phpmyfaq.de/advisory_2004-05-18.php - Vendor Advisory
References () http://www.securityfocus.com/archive/1/363636 - () http://www.securityfocus.com/archive/1/363636 -
References () http://www.securityfocus.com/bid/10377 - Patch () http://www.securityfocus.com/bid/10377 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16223 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16223 -

Information

Published : 2004-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2004-2256

Mitre link : CVE-2004-2256

CVE.ORG link : CVE-2004-2256


JSON object : View

Products Affected