CVE-2005-3929 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.5% (pctl 94)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the create function in xarMLSXML2PHPBackend.php in Xaraya 1.0 allows remote attackers to create directories and overwrite arbitrary files via ".." sequences in the module parameter to index.php.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 7.5% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xaraya | xaraya |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Xaraya 1.0.0 RC4 - 'create()' Denial of Service | 2005-11-29 |
References
- http://rgod.altervista.org/xaraya1DOS.hmtl
- http://secunia.com/advisories/17788
- http://securityreason.com/securityalert/217
- http://www.securityfocus.com/archive/1/418087/100/0/threaded
- http://www.securityfocus.com/archive/1/418191/100/0/threaded
- http://www.securityfocus.com/archive/1/418209/100/0/threaded
- http://www.securityfocus.com/bid/15623
- http://www.vupen.com/english/advisories/2005/2665
- http://rgod.altervista.org/xaraya1DOS.hmtl
- http://secunia.com/advisories/17788
- http://securityreason.com/securityalert/217
- http://www.securityfocus.com/archive/1/418087/100/0/threaded
- http://www.securityfocus.com/archive/1/418191/100/0/threaded
- http://www.securityfocus.com/archive/1/418209/100/0/threaded
- http://www.securityfocus.com/bid/15623
- http://www.vupen.com/english/advisories/2005/2665
→ the Explorer · watch your stack · NVD