{ "CVE_data_meta" : { "ASSIGNER" : "cve@mitre.org", "ID" : "CVE-2005-1201", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "n/a", "version" : { "version_data" : [ { "version_value" : "n/a" } ] } } ] }, "vendor_name" : "n/a" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "n/a" } ] } ] }, "references" : { "reference_data" : [ { "name" : "20050420 Multiple Security Issues Found In AZBB", "refsource" : "BUGTRAQ", "url" : "http://marc.info/?l=bugtraq&m=111401838521857&w=2" }, { "name" : "http://www.gulftech.org/?node=research&article_id=00068-04192005", "refsource" : "MISC", "url" : "http://www.gulftech.org/?node=research&article_id=00068-04192005" }, { "name" : "http://azbb.cyaccess.com/azbb.php?1091778548", "refsource" : "CONFIRM", "url" : "http://azbb.cyaccess.com/azbb.php?1091778548" }, { "name" : "15701", "refsource" : "OSVDB", "url" : "http://www.osvdb.org/15701" }, { "name" : "15702", "refsource" : "OSVDB", "url" : "http://www.osvdb.org/15702" }, { "name" : "15013", "refsource" : "SECUNIA", "url" : "http://secunia.com/advisories/15013" }, { "name" : "az-bulletin-board-file-modification(20180)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/20180" }, { "name" : "az-bulletin-board-file-existence(20183)", "refsource" : "XF", "url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/20183" } ] } }