faqmanager.cgi in FAQManager 2.2.5 and earlier allows remote attackers to read arbitrary files by specifying the filename in the toc parameter with a trailing null character (%00).
| Software | From | Fixed in |
|---|---|---|
| faqmanager / faqmanager.cgi | 2.2.1 | 2.2.1.x |
| faqmanager / faqmanager.cgi | 2.2 | 2.2.x |
| faqmanager / faqmanager.cgi | 2.2.4 | 2.2.4.x |
| faqmanager / faqmanager.cgi | 2.1.1 | 2.1.1.x |
| faqmanager / faqmanager.cgi | 2.2.3 | 2.2.3.x |
| faqmanager / faqmanager.cgi | 2.0 | 2.0.x |
| faqmanager / faqmanager.cgi | 2.2.5 | 2.2.5.x |
| faqmanager / faqmanager.cgi | 2.2.2 | 2.2.2.x |
| faqmanager / faqmanager.cgi | 2.1 | 2.1.x |
| faqmanager / faqmanager.cgi | 2.1.2 | 2.1.2.x |