>> ezDatabase "p" Parameter Handling Local File Inclusion Vulnerability
Title : ezDatabase "p" Parameter Handling Local File Inclusion Vulnerability VUPEN ID : VUPEN/ADV-2005-2942 CVE ID : CVE-2005-4302
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-12-16
Technical Description
A vulnerability has been identified in ezDatabase, which may be exploited by remote attackers to gain knowledge of sensitive information. This flaw is due to an input validation error in the "index.php" script that does not properly handle a specially crafted "p" parameter, which may be exploited by remote attackers to retrieve arbitrary files from a vulnerable system.