Back to search
CVE-2006-6175
Published: Nov 30, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
21341
vdb-entry
x_refsource_BID
1017316
vdb-entry
x_refsource_SECTRACK
ADV-2006-4775
vdb-entry
x_refsource_VUPEN
[horde-announce] 20061129 [SECURITY] Kronolith H3 (2.0.7) (final)
mailing-list
x_refsource_MLIST
23145
third-party-advisory
x_refsource_SECUNIA
20061129 Horde Kronolith Arbitrary Local File Inclusion Vulnerability
third-party-advisory
x_refsource_IDEFENSE
[horde-announce] 20061129 [SECURITY] Kronolith H3 (2.1.4) (final)
mailing-list
x_refsource_MLIST
GLSA-200701-11
vendor-advisory
x_refsource_GENTOO
23780
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now