Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3723 (phpizabi)

BugsAlert Home > CVE-2008-3723 (phpizabi)
 
 

Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a .. (dot dot), (2) a URL, or possibly (3) a full pathname in the id parameter in an admin.templates.edittemplate action. NOTE: some of these details are obtained from third party information.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3723

Learn more about CVE-2008-3723 (phpizabi)
 
Tags: cve-2008-3723 phpizabi

Related Items

      CVE-2008-4449 (mirc)

      FrSIRT - ViralDX "bannerid" Parameter Remote SQL Injection Vulnerability

      CVE-2008-4652 (powertcp_ftp_for_activex)

      CVE-2008-0010 (Kernel)

      TSPY_BZUB.A

      The Gemini Portal (lang) Remote File Inclusion Vulnerabilities

      I right click on an icon, choose "open", and nothing happens

 

Pixel