CVE-2006-1823 Information

Description

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ..\ sequences in the archive parameter to index.php which leaks the full pathname in an error message.

Reference

http://secunia.com/advisories/19648 http://securityreason.com/securityalert/710 http://securitytracker.com/id?1015943 http://www.securityfocus.com/archive/1/431011/100/0/threaded http://www.vupen.com/english/advisories/2006/1411

Share on: