Arbitrary File Read Vulnerability in phpCOIN 1.2.2

Arbitrary File Read Vulnerability in phpCOIN 1.2.2

CVE-2005-4212 · MEDIUM Severity

AV:N/AC:L/AU:N/C:P/I:N/A:N

Directory traversal vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote attackers to read arbitrary local files via ".." (dot dot) sequences in the $_CCFG[_PKG_PATH_DBSE] variable.

Learn more about our Web Application Penetration Testing UK.