CVE-2005-4600: Path Traversal
Published Dec 31, 2005
·Updated
Directory traversal vulnerability in tinymcegzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.
Affected Software
1 affected component
Moxiecode Tinymce Compressor Php<=1.05
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Jan 2, 2006
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4600?
CVE-2005-4600 has a moderate severity rating due to the potential for unauthorized file access.
2
How do I fix CVE-2005-4600?
To fix CVE-2005-4600, upgrade TinyMCE Compressor PHP to version 1.06 or later.
3
What vulnerabilities are associated with CVE-2005-4600?
CVE-2005-4600 is associated with a directory traversal vulnerability that allows reading or including arbitrary files.
4
Which versions of TinyMCE Compressor are affected by CVE-2005-4600?
Versions of TinyMCE Compressor PHP before 1.06 are affected by CVE-2005-4600.
5
What parameters are exploited in CVE-2005-4600?
CVE-2005-4600 is exploited through the theme, language, plugins, or lang parameters using a trailing null byte.