Vulnerabilities > CVE-2005-1201

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
azbb
exploit available

Summary

Multiple directory traversal vulnerabilities in AZ Bulletin board (AZbb) before 1.0.08 allow (1) remote authenticated users with administrative privileges to delete arbitrary files via a .. (dot dot) in the URL to admin_avatar.php or admin_attachment.php or (2) remote attackers to enumerate files via a .. (dot dot) in the attachment parameter to attachment.php, which displays a different message when a file exists or does not exist.

Exploit-Db

descriptionAZBB < 1.0.07d - Multiple Vulnerabilities. CVE-2005-1200,CVE-2005-1201. Webapps exploit for PHP platform
idEDB-ID:43823
last seen2018-01-24
modified2015-04-19
published2015-04-19
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43823/
titleAZBB < 1.0.07d - Multiple Vulnerabilities