CVE
- Id
- 6549
- CVE No.
- CVE-2002-2167
- Status
- Candidate
- Description
- Directory traversal vulnerability in function_foot_1.inc.php for Thorsten Korner 123tkShop before 0.3.1 allows remote attackers to read arbitrary files via .. (dot dot) sequences terminated by a null character in the $designNo variable, which is part of an "include" function call.
- Phase
- Assigned (20051116)
- Votes
- None (candidate not yet proposed)
- Comments