5
CVSSv2

CVE-2005-3929

Published: 30/11/2005 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote malicious users to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

xaraya xaraya 1.0_rc3

xaraya xaraya 1.0_rc4

xaraya xaraya 1.0_rc1

xaraya xaraya 1.0_rc2

Exploits

<?php # ---Xaraya_DOSphp 1730 28/11/2005 # # # # Xaraya <=100 RC4 DOS # # coded by rgod # # ...