peter bassill · operator
$ cve CVE-2005-4095 JSON

CVE-2005-4095 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in connector.php in the fckeditor2rc2 addon in DoceboLMS 2.0.4 allows remote attackers to list arbitrary files and directories via ".." sequences in the Type parameter in a GetFoldersAndFiles command.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS8.47% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-12-08
Last modified2026-06-16

Affected (1)

VendorProduct
docebolmsdocebolms

Public exploits

SourceTitleDate
exploit-dbDoceboLms 2.0.4 - 'connector.php' Arbitrary File Upload2005-12-04

References

→ the Explorer  ·  watch your stack  ·  NVD