Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-0742
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0742

Description:
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators.

CVE Status:
Candidate

References:

SREASON
  http://securityreason.com/securityalert/3647

MILW0RM
  http://www.milw0rm.com/exploits/5082

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/487773/100/0/threaded

BID
  27688


Return to the previous page.