Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-04-18T10:00:00

Updated: 2018-10-18T14:57:01

Reserved: 2006-04-17T00:00:00


Link: CVE-2006-1823

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-04-18T10:02:00.000

Modified: 2018-10-18T16:36:41.643


Link: CVE-2006-1823

JSON object: View

cve-icon Redhat Information

No data.