Vulnerabilities > CVE-2006-0315 - Unspecified vulnerability in Indexcor Ezdatabase
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN indexcor
exploit available
Summary
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | EZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability. CVE-2006-0315. Webapps exploit for php platform |
id | EDB-ID:27093 |
last seen | 2016-02-03 |
modified | 2006-01-16 |
published | 2006-01-16 |
reporter | Josh Zlatin-Amishav |
source | https://www.exploit-db.com/download/27093/ |
title | EZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html
- http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0515.html
- http://secunia.com/advisories/18043
- http://secunia.com/advisories/18043
- http://www.osvdb.org/22684
- http://www.osvdb.org/22684
- http://www.securityfocus.com/archive/1/422071/100/0/threaded
- http://www.securityfocus.com/archive/1/422071/100/0/threaded
- http://www.securityfocus.com/bid/16257
- http://www.securityfocus.com/bid/16257
- http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt
- http://zur.homelinux.com/Advisories/ezdatabase_dir_trans.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24134
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24134
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24135
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24135