Vulnerabilities > CVE-2005-3910 - Directory Traversal vulnerability in Post Affiliate PRO Post Affiliate PRO 2.0.4

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
post-affiliate-pro

Summary

merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.

Vulnerable Configurations

Part Description Count
Application
Post_Affiliate_Pro
1