PT-2006-6806 · Horde · Horde Kronolith H3
Publicado
2006-11-30
·
Atualizado
2016-10-18
·
CVE-2006-6175
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Horde Kronolith H3 versions 2.0.0 through 2.0.6
Horde Kronolith H3 version 2.1.x prior to 2.1.4
Description
The issue allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the
view parameter. This is a directory traversal vulnerability in the lib/FBView.php file.Recommendations
For Horde Kronolith H3 versions 2.0.0 through 2.0.6, update to version 2.0.7 or later.
For Horde Kronolith H3 version 2.1.x prior to 2.1.4, update to version 2.1.4 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Horde Kronolith H3