CVE-2006-5733: High severity Postnuke Software Foundation Postnuke vulnerability
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5733?
CVE-2006-5733 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2006-5733?
To fix CVE-2006-5733, upgrade to PostNuke version 0.764 or later, which addresses the directory traversal vulnerability.
Which versions of PostNuke are affected by CVE-2006-5733?
CVE-2006-5733 affects PostNuke versions 0.763 and earlier.
What type of attack does CVE-2006-5733 enable?
CVE-2006-5733 enables attackers to perform directory traversal attacks leading to the inclusion and execution of arbitrary local files.
Can CVE-2006-5733 allow remote attackers to execute arbitrary code?
Yes, CVE-2006-5733 allows remote attackers to execute arbitrary code on the affected PostNuke installation.