Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1492
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1492

Description:
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41394

SREASON
  http://securityreason.com/securityalert/3772

SAID
  Secunia Advisory: SA29514

MISC
  http://0x90.com.ar/Advisory/20080321.txt

MILW0RM
  http://www.milw0rm.com/exploits/5288

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/491525/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/489971/100/0/threaded

BID
  28397


Return to the previous page.