CVE-2004-1505

Publication date

2005-02-19 05:00:00

Family

mitre

State

PUBLISHED

Description

Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.