CVE-2004-2255: Medium severity PhpMyFaq phpmyfaq vulnerability
Published Dec 31, 2004
·Updated
Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.
Affected Software
1 affected component
PhpMyFaq phpmyfaq=1.3.12
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2255?
CVE-2004-2255 is considered a critical vulnerability due to its potential to allow unauthorized file access and execution of local PHP scripts.
2
How do I fix CVE-2004-2255?
To fix CVE-2004-2255, upgrade phpMyFAQ to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2004-2255?
CVE-2004-2255 specifically affects phpMyFAQ version 1.3.12.
4
Can CVE-2004-2255 lead to remote code execution?
Yes, CVE-2004-2255 may allow remote attackers to execute local PHP files, which can lead to remote code execution.
5
What is the nature of the vulnerability in CVE-2004-2255?
The nature of the vulnerability in CVE-2004-2255 is a directory traversal vulnerability that allows reading of arbitrary files.