CVE-2010-2006

Publication date 20 May 2010

Last updated 24 July 2024


Ubuntu priority

Directory traversal vulnerability in op/op.Login.php in LetoDMS (formerly MyDMS) 1.7.2 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
mydms 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy
Fixed 1.7.0-1+lenny1build0.8.04.1
6.06 LTS dapper Ignored end of life

Notes


jdstrand

aka LetoDMS