7.5
CVSSv2

CVE-2005-0411

Published: 14/02/2005 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and previous versions allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

citrusdb citrusdb

Exploits

source: wwwsecurityfocuscom/bid/12564/info CitrusDB is reportedly affected by a vulnerability that permits the inclusion of any local PHP file This issue is due to the application failing to properly sanitize user-supplied input This issue is reported to affect CitrusDB 036; earlier versions may also be affected This issue may also ...