VulnerabilityModified
CVE-2004-2256
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.
MEDIUM 5.0EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.htmlVendor Advisory
- http://secunia.com/advisories/11640Patch, Vendor Advisory
- http://securitytracker.com/id?1010190Patch
- http://www.phpmyfaq.de/advisory_2004-05-18.phpVendor Advisory
- http://www.securityfocus.com/archive/1/363636
- http://www.securityfocus.com/bid/10377Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16223
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0906.htmlVendor Advisory
- http://secunia.com/advisories/11640Patch, Vendor Advisory
- http://securitytracker.com/id?1010190Patch
- http://www.phpmyfaq.de/advisory_2004-05-18.phpVendor Advisory
- http://www.securityfocus.com/archive/1/363636
- http://www.securityfocus.com/bid/10377Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16223
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.