Directory traversal vulnerability in (1) edit_mailtexte.cgi and (2) bestmail.cgi in Cosmoshop 8.11.106 and earlier allows remote administrators to read arbitrary files via ".." sequences in the file parameter.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2006-05-19T17:00:00
Updated: 2024-08-07T17:51:04.585Z
Reserved: 2006-05-19T00:00:00
Link: CVE-2006-2475

No data.

Status : Deferred
Published: 2006-05-19T17:02:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-2475

No data.