Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-6175
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-6175

Description:
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.

CVE Status:
Candidate

References:

ST
  1017316

SAID
  Secunia Advisory: SA23145
  Secunia Advisory: SA23780

MLIST
  http://marc.theaimsgroup.com/?l=horde-announce&m=116483107007152&w=2
  http://marc.theaimsgroup.com/?l=horde-announce&m=116483121211579&w=2

IDEFENSE
  http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=445

GENTOO
  http://security.gentoo.org/glsa/glsa-200701-11.xml

BID
  21341


Return to the previous page.