5

CVE-2006-0244

Exploit
Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter.  NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpxplorerPhpxplorer Version0.9.33
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.06% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18518
Vendor Advisory
http://securityreason.com/securityalert/353
http://www.arrelnet.com/advisories/adv20060116.html
Vendor Advisory
Exploit
http://www.securityfocus.com/archive/1/421997/100/0/threaded
http://www.securityfocus.com/archive/1/422158/100/0/threaded
http://www.securityfocus.com/bid/16263
Exploit
http://www.vupen.com/english/advisories/2006/0232
https://exchange.xforce.ibmcloud.com/vulnerabilities/39982