Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.
References
Link | Resource |
---|---|
http://guff.szub.net/2005/07/04/quick-and-dirty-security/ | Exploit Vendor Advisory |
http://securitytracker.com/id?1014376 | Exploit |
http://secunia.com/advisories/15900 | Exploit Vendor Advisory |
Configurations
Information
Published : 2005-07-05 21:00
Updated : 2008-09-05 13:51
NVD link : CVE-2005-2169
Mitre link : CVE-2005-2169
JSON object : View
CWE
Products Affected
kaf_oseo
- quick_and_dirty_phpsource_printer