Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-02-24 03:02
Updated : 2011-03-06 21:00
NVD link : CVE-2006-0871
Mitre link : CVE-2006-0871
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
mambo
- mambo