CVE-2005-1699: Medium severity Postnuke Software Foundation Postnuke vulnerability
Published May 24, 2005
·Updated
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.
Affected Software
1 affected component
Postnuke Software Foundation Postnuke=0.760_rc3
Event History
May 24, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1699?
CVE-2005-1699 is classified as a critical vulnerability due to its ability to allow remote file disclosure.
2
How do I fix CVE-2005-1699?
To mitigate CVE-2005-1699, upgrade to a version of PostNuke that is not affected, specifically later than 0.760-RC3.
3
What types of attacks can exploit CVE-2005-1699?
CVE-2005-1699 can be exploited via directory traversal attacks that allow unauthorized access to sensitive files.
4
Who is affected by CVE-2005-1699?
Any remote administrator using PostNuke version 0.760-RC3 is vulnerable to CVE-2005-1699.
5
What are the implications of CVE-2005-1699?
Exploitation of CVE-2005-1699 can lead to exposure of sensitive system files, potentially compromising the security of the server.