6.4
CVSSv2

CVE-2005-1201

Published: 02/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) prior to 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote malicious users to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.

Vulnerable Product Search on Vulmon Subscribe to Product

Exploits

AZBB Multiple Vulnerabilities Vendor: AZBB Product: AZBB Version: <= 1007d Website: azbbcyaccesscom/ BID: 13272 13278 CVE: CVE-2005-1200 CVE-2005-1201 OSVDB: 15700 15701 15702 15703 SECUNIA: 15013 PACKETSTORM: 37792 Description: azbb is a forum that was written with a primary focus on security azbb does not require a database ...