Back
CVE-2004-1505
Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| salims_softhouse | jaf_cms | 3.0 |
GitHub Security Advisory GHSA-rf3w-gh9w-j7g5
Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows...
References (10)
- http://echo.or.id/adv/adv08-y3dips-2004.txt Exploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=110004150430309&w=2
- http://secunia.com/advisories/13104 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11627 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17983
- http://echo.or.id/adv/adv08-y3dips-2004.txt Exploit, Vendor Advisory
- http://marc.info/?l=bugtraq&m=110004150430309&w=2
- http://secunia.com/advisories/13104 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11627 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17983
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
2.00%
Top 21% most likely to be exploited
Threat Score
30.6 / 100
Data Sources
NVD
EPSS
GitHub