Security Advisory

CVE-2004-0344

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2004-03-18 05:00:00
Last updated 2024-08-08 00:17:14
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in ModifyMessage.php in YaBB SE 1.5.4 through 1.5.5b allows remote attackers to delete arbitrary files via a .. (dot dot) in the attachOld parameter.