Heap
08-10-08, 02:46
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the language cookie.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4455)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4455)