CVE Vulnerabilities

CVE-2005-1201

Published: May 02, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.

Affected Software

NameVendorStart VersionEnd Version
Az_bulletin_boardAzbb1.0.07a (including)1.0.07a (including)
Az_bulletin_boardAzbb1.0.07b (including)1.0.07b (including)
Az_bulletin_boardAzbb1.0.07c (including)1.0.07c (including)
Az_bulletin_boardAzbb1.0.07d (including)1.0.07d (including)

References