index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-11-16T07:37:00
Updated: 2016-10-17T13:57:01
Reserved: 2005-11-16T00:00:00
Link: CVE-2005-3592
JSON object: View
NVD Information
Status : Modified
Published: 2005-11-16T07:42:00.000
Modified: 2016-10-18T03:36:24.610
Link: CVE-2005-3592
JSON object: View
Redhat Information
No data.
CWE