Vulnerabilities > CVE-2004-0327 - Unspecified vulnerability in Skintech PHPnewsmanager 1.36

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
skintech
exploit available

Summary

Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.

Vulnerable Configurations

Part Description Count
Application
Skintech
1

Exploit-Db

  • descriptionPHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (2). CVE-2002-0229,CVE-2004-0327. Remote exploit for php platform
    idEDB-ID:21265
    last seen2016-02-02
    modified2002-02-03
    published2002-02-03
    reporteranonymous
    sourcehttps://www.exploit-db.com/download/21265/
    titlePHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability 2
  • descriptionPHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (1). CVE-2002-0229,CVE-2004-0327. Remote exploit for php platform
    idEDB-ID:21264
    last seen2016-02-02
    modified2002-02-03
    published2002-02-03
    reporterDave Wilson
    sourcehttps://www.exploit-db.com/download/21264/
    titlePHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability 1
  • descriptionPHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability (3). CVE-2002-0229,CVE-2004-0327. Remote exploit for php platform
    idEDB-ID:21266
    last seen2016-02-02
    modified2002-02-03
    published2002-02-03
    reporteranonymous
    sourcehttps://www.exploit-db.com/download/21266/
    titlePHP 4.x/5.x MySQL Safe_Mode Filesystem Circumvention Vulnerability 3
  • descriptionphpNewsManager 1.36 Functions Script File Disclosure Vulnerability. CVE-2004-0327. Webapps exploit for php platform
    idEDB-ID:23742
    last seen2016-02-02
    modified2004-02-23
    published2004-02-23
    reporterG00db0y
    sourcehttps://www.exploit-db.com/download/23742/
    titlephpNewsManager 1.36 Functions Script File Disclosure Vulnerability