Vulnerabilities > CVE-2006-0315 - Cross-Site Scripting vulnerability in EZDatabase

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
indexcor
exploit available

Summary

index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.

Vulnerable Configurations

Part Description Count
Application
Indexcor
1

Exploit-Db

descriptionEZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability. CVE-2006-0315. Webapps exploit for php platform
idEDB-ID:27093
last seen2016-02-03
modified2006-01-16
published2006-01-16
reporterJosh Zlatin-Amishav
sourcehttps://www.exploit-db.com/download/27093/
titleEZDatabase 2.1.1 Index.PHP Cross-Site Scripting Vulnerability