Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
References
Configurations
History
No history.
Information
Published : 2006-11-14 22:07
Updated : 2025-04-09 00:30
NVD link : CVE-2006-5894
Mitre link : CVE-2006-5894
CVE.ORG link : CVE-2006-5894
JSON object : View
Products Affected
rama_cms
- rama_cms
CWE