CVE-2006-0315
N/A
N/A
Summary
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/16257
- http://www.securityfocus.com/archive/1/422071/100/0/threaded
- http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24134
- http://secunia.com/advisories/18043
- http://www.osvdb.org/22684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24135
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html
References
- http://www.securityfocus.com/bid/16257
- http://www.securityfocus.com/archive/1/422071/100/0/threaded
- http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24134
- http://secunia.com/advisories/18043
- http://www.osvdb.org/22684
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24135
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.