Vulnerabilities > CVE-2004-0071 - Information Disclosure vulnerability in Andy's PHP Projects Man Page Lookup Script

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
exploit available

Summary

Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote attackers to read arbitrary files via the command parameter ($cmd variable) to index.php.

Exploit-Db

descriptionAndy's PHP Projects Man Page Lookup Script Information Disclosure Vulnerability. CVE-2004-0071. Webapps exploit for php platform
idEDB-ID:23536
last seen2016-02-02
modified2004-01-10
published2004-01-10
reporterCabezon Aurelien
sourcehttps://www.exploit-db.com/download/23536/
titleAndy's PHP Projects Man Page Lookup Script Information Disclosure Vulnerability