CVE-2006-0567
N/A
N/A
Summary
Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24393
- http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things
- http://www.vupen.com/english/advisories/2006/0371
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24393
- http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things
- http://www.vupen.com/english/advisories/2006/0371
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.