First published: Fri Dec 31 2004(Updated: )
Directory traversal vulnerability in phpMyFAQ 1.4.0 alpha allows remote attackers to read arbitrary files, and possibly execute local PHP files, via .. sequences in the lang (language) variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =1.4_alpha1 | |
phpMyFAQ | =1.4_alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2256 is classified as a medium severity vulnerability.
To fix CVE-2004-2256, upgrade phpMyFAQ to a patched version beyond 1.4.0 alpha.
CVE-2004-2256 specifically affects phpMyFAQ version 1.4.0 alpha.
The main impact of CVE-2004-2256 is the potential for unauthorized file access or execution via directory traversal.
CVE-2004-2256 can be exploited by remote attackers with access to the application, allowing them to leverage the vulnerability.