CVE-2005-4424

Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpkit:phpkit:1.6.02:*:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.1:rc2:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.03:*:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.1:*:*:*:*:*:*:*

Information

Published : 2005-12-20 03:03

Updated : 2017-07-19 18:29


NVD link : CVE-2005-4424

Mitre link : CVE-2005-4424


JSON object : View

Advertisement

dedicated server usa

Products Affected

phpkit

  • phpkit