5.1
CVSSv2

CVE-2006-2747

Published: 01/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote malicious users to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.

Vulnerable Product Search on Vulmon Subscribe to Product

fredi bach phpmydesktop arcade

Exploits

source: wwwsecurityfocuscom/bid/18185/info phpMyDesktop|arcade is prone to a local file-include vulnerability This may allow unauthorized users to view files and to execute local scripts An attacker may also be able to execute arbitrary code by way of uploaded images wwwexamplecom/indexphp?todo=showsubsite&subsite=[file ...