Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-01-09T11:00:00

Updated: 2018-10-19T14:57:01

Reserved: 2006-01-09T00:00:00


Link: CVE-2006-0132

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-01-09T11:03:00.000

Modified: 2018-10-19T15:42:45.543


Link: CVE-2006-0132

JSON object: View

cve-icon Redhat Information

No data.