CVE Vulnerabilities

CVE-2006-4234

Published: Aug 18, 2006 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

Affected Software

Name Vendor Start Version End Version
Dotproject Dotproject 2.0 (including) 2.0 (including)
Dotproject Dotproject 2.0.1 (including) 2.0.1 (including)
Dotproject Dotproject 2.0.2 (including) 2.0.2 (including)
Dotproject Dotproject 2.0.4 (including) 2.0.4 (including)

References