Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://secunia.com/advisories/18935 | third party advisory patch vendor advisory |
http://www.vupen.com/english/advisories/2006/0719 | vdb entry vendor advisory |
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html | mailing list |
http://www.gulftech.org/?node=research&article_id=00104-02242006 | |
http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/ | patch |
http://securityreason.com/securityalert/493 | third party advisory |
http://www.osvdb.org/23505 | vdb entry |