Directory traversal vulnerability in PHPList 2.10.2 and earlier allows remote attackers to include arbitrary local files via the (1) GLOBALS[database_module] or (2) GLOBALS[language_module] parameters, which overwrite the underlying $GLOBALS variable.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2006-04-12 22:02
Updated : 2017-07-20 01:30
NVD link : CVE-2006-1746
Mitre link : CVE-2006-1746
CVE.ORG link : CVE-2006-1746
JSON object : View
Products Affected
tincan
- phplist
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')