Phpmydesktop · Phpmydesktop/Arcade · CVE-2006-2747
**Name of the Vulnerable Software and Affected Versions**
PhpMyDesktop|arcade version 1.0 FINAL
**Description**
The issue allows remote attackers to read arbitrary files or execute PHP code. This is achieved by using a .. (dot dot) sequence and a trailing null (%00) byte in the `subsite` parameter within a showsubsite todo request to the "index.php" file.
**Recommendations**
For PhpMyDesktop|arcade version 1.0 FINAL, as a temporary workaround, consider restricting access to the `subsite` parameter in the "index.php" file until a patch is available. Avoid using the `subsite` parameter with a .. (dot dot) sequence and a trailing null (%00) byte in the showsubsite todo request to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.