Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-02-07T18:00:00

Updated: 2024-08-07T16:41:28.987Z

Reserved: 2006-02-07T00:00:00

Link: CVE-2006-0567

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-02-07T18:06:00.000

Modified: 2017-07-20T01:29:53.050

Link: CVE-2006-0567

cve-icon Redhat

No data.