Unrated severityNVD Advisory· Published Dec 31, 2005· Updated Apr 16, 2026
CVE-2005-4600
CVE-2005-4600
Description
Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE Compressor PHP before 1.06 allows remote attackers to read or include arbitrary files via a trailing null byte (%00) in the (1) theme, (2) language, (3) plugins, or (4) lang parameter.
Affected products
1- cpe:2.3:a:moxiecode:tinymce_compressor_php:*:*:*:*:*:*:*:*Range: <=1.05
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- secunia.com/advisories/18262nvdPatchVendor Advisory
- tinymce.moxiecode.com/punbb/viewtopic.phpnvdPatch
- www.securityfocus.com/bid/16083nvdPatch
- www.hardened-php.net/advisory_262005.111.htmlnvdVendor Advisory
- securityreason.com/securityalert/306nvd
- securitytracker.com/idnvd
- tinymce.moxiecode.com/punbb/viewtopic.phpnvd
- www.osvdb.org/22116nvd
- www.securityfocus.com/archive/1/420543/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/36736nvd
- www.exploit-db.com/exploits/4441nvd
News mentions
0No linked articles in our index yet.