5

CVE-2005-2256

Exploit
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhppgadminPhppgadmin Version3.1
PhppgadminPhppgadmin Version3.2
PhppgadminPhppgadmin Version3.3
PhppgadminPhppgadmin Version3.4
PhppgadminPhppgadmin Version3.4.1
PhppgadminPhppgadmin Version3.5.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.64% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/dailydave/2005-q3/0010.html
http://secunia.com/advisories/15941
Vendor Advisory
http://secunia.com/advisories/16116
http://securitytracker.com/id?1014414
Exploit
http://sourceforge.net/project/shownotes.php?release_id=342261
http://www.debian.org/security/2005/dsa-759
http://www.securityfocus.com/bid/14142
Exploit
http://www.vuxml.org/freebsd/88188a8c-eff6-11d9-8310-0001020eed82.html
Vendor Advisory