Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1346
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1346

Description:
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA19322

OSVDB
  24016

MLIST
  http://attrition.org/pipermail/vim/2006-April/000698.html

MISC
  http://www.milw0rm.com/exploits/1595

BID
  17165


Return to the previous page.