Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-02-24 11:02
Updated : 2011-03-07 05:00
NVD link : CVE-2006-0871
Mitre link : CVE-2006-0871
CVE.ORG link : CVE-2006-0871
JSON object : View
Products Affected
mambo
- mambo
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')