MEDIUM · 4.0

CVE-2006-0445

index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display...

Vulnerability Description

index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display the full path of uploader.php. NOTE: this might be the result of a file inclusion vulnerability.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
PhpclanwebsitePhpclanwebsite1.23.1

References

FAQ

What is CVE-2006-0445?

CVE-2006-0445 is a vulnerability with a CVSS score of 4.0 (MEDIUM). index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display...

How severe is CVE-2006-0445?

CVE-2006-0445 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0445?

Check the references section above for vendor advisories and patch information. Affected products include: Phpclanwebsite Phpclanwebsite.