CVE-2005-4600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
31/12/2005
Last modified:
03/04/2025

Description

Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moxiecode:tinymce_compressor_php:*:*:*:*:*:*:*:* 1.05 (including)