CVE Vulnerabilities

CVE-2005-2255

Published: Jul 13, 2005 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via .. sequences in the lan parameter to (1) index.php or (2) admin/index.php.

Affected Software

Name Vendor Start Version End Version
Phpauction Gianluca_baldo 2.5 2.5

References