PT-2005-4688 · Php · Phpalbum

Published

2005-12-01

·

Updated

2008-10-03

·

CVE-2005-3948

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPAlbum versions 0.2.3 and earlier
Description A directory traversal issue exists, allowing remote attackers to read arbitrary files. This is achieved via the cmd and var1 parameters.
Recommendations For PHPAlbum versions 0.2.3 and earlier, avoid using the cmd and var1 parameters in the affected main.php file until a fix is available. As a temporary workaround, consider restricting access to main.php to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3948

Affected Products

Phpalbum