Back
CVE-2005-3550
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.
Published: Nov 16, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| toenda_software_development | toendacms | * |
GitHub Security Advisory GHSA-rx49-ffc3-rw37
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers...
References (8)
- http://secunia.com/advisories/17471 Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415975/30/0/threaded
- http://www.securityfocus.com/bid/15348
- http://www.vupen.com/english/advisories/2005/2343
- http://secunia.com/advisories/17471 Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/415975/30/0/threaded
- http://www.securityfocus.com/bid/15348
- http://www.vupen.com/english/advisories/2005/2343
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
6.28%
Top 7% most likely to be exploited
Threat Score
21.9 / 100
Data Sources
NVD
EPSS
GitHub