Vulnerabilities > CVE-2006-6175 - Unspecified vulnerability in Horde Kronolith
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN horde
nessus
Summary
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 10 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200701-11.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200701-11 (Kronolith: Local file inclusion) Kronolith contains a mistake in lib/FBView.php where a raw, unfiltered string is used instead of a sanitized string to view local files. Impact : An authenticated attacker could craft an HTTP GET request that uses directory traversal techniques to execute any file on the web server as PHP code, which could allow information disclosure or arbitrary code execution with the rights of the user running the PHP application (usually the webserver user). Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24209 |
published | 2007-01-17 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24209 |
title | GLSA-200701-11 : Kronolith: Local file inclusion |
code |
|
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=445
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=445
- http://marc.info/?l=horde-announce&m=116483107007152&w=2
- http://marc.info/?l=horde-announce&m=116483107007152&w=2
- http://marc.info/?l=horde-announce&m=116483121211579&w=2
- http://marc.info/?l=horde-announce&m=116483121211579&w=2
- http://secunia.com/advisories/23145
- http://secunia.com/advisories/23145
- http://secunia.com/advisories/23780
- http://secunia.com/advisories/23780
- http://security.gentoo.org/glsa/glsa-200701-11.xml
- http://security.gentoo.org/glsa/glsa-200701-11.xml
- http://securitytracker.com/id?1017316
- http://securitytracker.com/id?1017316
- http://www.securityfocus.com/bid/21341
- http://www.securityfocus.com/bid/21341
- http://www.vupen.com/english/advisories/2006/4775
- http://www.vupen.com/english/advisories/2006/4775