Description
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:41:29.153Z
Reserved: 2006-02-13T00:00:00.000Z
Link: CVE-2006-0660
No data.
Status : Deferred
Published: 2006-02-13T11:06:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-0660
No data.
OpenCVE Enrichment
No data.
Weaknesses