Back

CVE-2004-2255

Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary files, and possibly execute local PHP files, via the action variable, which is used as part of a template filename.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
phpmyfaq phpmyfaq 1.3.12

GitHub Security Advisory GHSA-j9vh-w3pf-6mgg

Directory traversal vulnerability in phpMyFAQ 1.3.12 allows remote attackers to read arbitrary...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.98%

Top 21% most likely to be exploited

Threat Score 26.2 / 100

Data Sources

NVD EPSS GitHub