Vulnerabilities > CVE-2006-0315 - Unspecified vulnerability in Indexcor Ezdatabase

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
indexcor
exploit available

Summary

index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.

Vulnerable Configurations

Part Description Count
Application
Indexcor
1

Exploit-Db

descriptionEZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability. CVE-2006-0315. Webapps exploit for php platform
idEDB-ID:27093
last seen2016-02-03
modified2006-01-16
published2006-01-16
reporterJosh Zlatin-Amishav
sourcehttps://www.exploit-db.com/download/27093/
titleEZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability