Vulnerabilities > CVE-2004-2255 - Unspecified vulnerability in PHPmyfaq 1.3.12

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
phpmyfaq
nessus

Summary

Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

Vulnerable Configurations

Part Description Count
Application
Phpmyfaq
1

Nessus

NASL familyCGI abuses
NASL idPHPMYFAQ_ACTION_PARAMETER_FLAW.NASL
descriptionThe version of phpMyFAQ on the remote host contains a flaw that may lead to an unauthorized information disclosure. The problem is that user input passed to the
last seen2020-06-01
modified2020-06-02
plugin id14258
published2004-08-11
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14258
titlephpMyFAQ index.php action Parameter Local File Inclusion