CVE-2005-4424

Directory traversal vulnerability in PHPKIT 1.6.1 R2 and earlier might allow remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the path parameter and a %00 at the end of the filename, as demonstrated by an avatar filename ending with .png%00.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpkit:phpkit:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.1:rc2:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.02:*:*:*:*:*:*:*
cpe:2.3:a:phpkit:phpkit:1.6.03:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-12-20 11:03

Updated : 2024-02-04 16:52


NVD link : CVE-2005-4424

Mitre link : CVE-2005-4424

CVE.ORG link : CVE-2005-4424


JSON object : View

Products Affected

phpkit

  • phpkit