Description
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.
Published: 2006-05-30
Score: 4.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2006-2632 Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.
History

No history.

Subscriptions

Andrew Godwin Bytehoard
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T17:58:51.669Z

Reserved: 2006-05-30T00:00:00.000Z

Link: CVE-2006-2633

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-05-30T10:02:00.000

Modified: 2026-04-16T00:27:16.627

Link: CVE-2006-2633

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses