Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.
CVSS Vector
AV:N/AC:L/Au:N/C:P/I:P/A:PCitrusdb
APPCitrusdb≤ 0.3.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
Related vulnerabilities
CVE-2005-0408CRITICAL9.8PL ✓same product
CitrusDB: pominięcie uwierzytelnienia przez przewidywalny hash MD5 cookie
CVE-2005-0409MEDIUM6.4same product
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which ...
CVE-2005-0410MEDIUM5.0same product
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject d...
CVE-2005-0229MEDIUM5.0same vendor
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote ...