CVE-2005-4600

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:moxiecode:tinymce_compressor_php:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2005-12-31 05:00

Updated : 2023-12-10 10:28


NVD link : CVE-2005-4600

Mitre link : CVE-2005-4600

CVE.ORG link : CVE-2005-4600


JSON object : View

Products Affected

moxiecode

  • tinymce_compressor_php
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')