Description
Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a cookie, as demonstrated by using error.php to insert malicious code into a log file, or uploading a malicious .png file, which is then included using install.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:41:28.838Z
Reserved: 2006-02-10T00:00:00.000Z
Link: CVE-2006-0644
No data.
Status : Deferred
Published: 2006-02-10T11:02:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0644
No data.
OpenCVE Enrichment
No data.
Weaknesses