CVE-2013-1806: Path Traversal
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) usertheme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/userfields.php or (3) file parameter to administration/dbbackup.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1806?
CVE-2013-1806 is classified with a moderate severity level due to its potential impact on file inclusion and deletion.
How do I fix CVE-2013-1806?
To fix CVE-2013-1806, you should upgrade PHP-Fusion to version 7.02.06 or later, which addresses these vulnerabilities.
What types of attacks can be executed due to CVE-2013-1806?
Due to CVE-2013-1806, attackers can perform directory traversal leading to unauthorized file inclusion or execution.
Who is affected by CVE-2013-1806?
CVE-2013-1806 affects all remote authenticated users and administrators of PHP-Fusion versions prior to 7.02.06.
Is CVE-2013-1806 specific to certain PHP-Fusion versions?
Yes, CVE-2013-1806 specifically affects PHP-Fusion versions 7.02.05 and earlier, including 7.02.01 through 7.02.04.