PT-2006-6508 · Opensolution · Opensolution Quick.Cms.Lite

Kacper

·

Published

2006-11-10

·

Updated

2017-10-19

·

CVE-2006-5834

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OpenSolution Quick.Cms.Lite version 0.3
Description: A directory traversal issue exists, allowing remote attackers to include arbitrary files by using a .. (dot dot) sequence in the sLanguage Cookie parameter.
Recommendations: For OpenSolution Quick.Cms.Lite version 0.3, consider restricting access to the general.php file until a patch is available, and avoid using the sLanguage Cookie parameter with untrusted input.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5834

Affected Products

Opensolution Quick.Cms.Lite