CVE Database
/

CVE-2005-3048

Back to search

CVE-2005-3048

Published: Sep 23, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file.

VendorProductVersions

n/a

n/a

affected
n/a

References

19672
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now