Sploitus

CVE-2006-5733

1 known exploit for CVE-2006-5733

Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

Affected products
Apache Http Server, Postnuke
Postnuke Software Foundation Postnuke
≤ 0.763, 0.762
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
3.0% (86th percentile)
NVD status
Modified
Published
2006-11-06
CVE-2006-5733 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-5733

Proof-of-concept code and exploit modules indexed by Sploitus