Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-1003
Description:Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.
Test IDs: 1.3.6.1.4.1.25623.1.0.100546  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-1003
BugTraq ID: 38787
http://www.securityfocus.com/bid/38787
Bugtraq: 20100316 CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability (Google Search)
http://www.securityfocus.com/archive/1/510155/100/0/threaded
http://www.coresecurity.com/content/efront-php-file-inclusion
http://osvdb.org/63028




© 1998-2025 E-Soft Inc. All rights reserved.