Description
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2172-1 | moodle security update |
EUVD |
EUVD-2010-3676 | Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T03:18:52.594Z
Reserved: 2010-10-01T00:00:00.000Z
Link: CVE-2010-3692
No data.
Status : Deferred
Published: 2010-10-07T21:00:02.017
Modified: 2025-04-11T00:51:21.963
Link: CVE-2010-3692
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD