CVE-2006-0567 Information

Description

Directory traversal vulnerability in Files Xaraya module before 0.5.1 when the Archive Directory field on the Modify Config page is blank allows remote attackers to access files outside of the web root via ..\ (dot dot) sequences.

Reference

http://www.vupen.com/english/advisories/2006/0371 http://xaraya.curtisfarnham.com/articles/Files_0.5.1_-_Security_Fix_and_other_things https://exchange.xforce.ibmcloud.com/vulnerabilities/24393

Share on: