CVE-2006-5149

Publication date

2006-10-03 03:00:00

Family

mitre

State

PUBLISHED

Description

Multiple directory traversal vulnerabilities in OpenBiblio before 0.5.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the page parameter to shared/help.php or (2) the tab parameter to shared/header.php.