CVE-2005-0947 Information

Description

Directory traversal vulnerability in auxpage.php in phpCoin 1.2.1b and earlier allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the page parameter.

Reference

http://marc.info/?l=bugtraq&m=111214190111520&w=2 http://www.gulftech.org/?node=research&article_id=00065-03292005 http://www.securityfocus.com/bid/12917 https://exchange.xforce.ibmcloud.com/vulnerabilities/19896

Share on: