mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 11:06:19 +00:00
904 B
904 B
CVE-2005-2951
Description
Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.
POC
Reference
- http://marc.info/?l=bugtraq&m=112662698511403&w=2
- http://marc.info/?l=bugtraq&m=112662698511403&w=2
- http://securityreason.com/securityalert/5
- http://securityreason.com/securityalert/5
Github
No PoCs found on GitHub currently.