Vulnerabilities > CVE-2005-2997 - Directory Traversal vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.30

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
bugada-andrea

Summary

Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php.

Vulnerable Configurations

Part Description Count
Application
Bugada_Andrea
1