Vulnerabilities > CVE-2005-0293 - Remote Directory Traversal vulnerability in Minis 0.2.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
minis
nessus

Summary

Directory traversal vulnerability in minis.php in Minis 0.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the month parameter.

Vulnerable Configurations

Part Description Count
Application
Minis
1

Nessus

NASL familyCGI abuses
NASL idMINIS_FILE_READING.NASL
descriptionThe remote host is running Minis, a weblogging system written in PHP. The remote version of this software is vulnerable to a directory traversal attack. Input to the
last seen2020-06-01
modified2020-06-02
plugin id16179
published2005-01-17
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/16179
titleMinis minis.php month Parameter Traversal Arbitrary File Access