Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-04-12 15:02
Updated : 2017-07-19 18:30
NVD link : CVE-2006-1746
Mitre link : CVE-2006-1746
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
tincan
- phplist