Security Advisory

CVE-2005-1840

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-06-02 04:00:00
Last updated 2024-08-07 22:06:57
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.