5
CVE-2006-0847
- EPSS 2.33%
- Veröffentlicht 22.02.2006 02:02:00
- Zuletzt bearbeitet 16.06.2026 22:21:24
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.33% | 0.813 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306
http://secunia.com/advisories/18944
http://secunia.com/advisories/20344
http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099
http://www.cherrypy.org/
http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml
http://www.securityfocus.com/bid/16760
http://www.vupen.com/english/advisories/2006/0677
https://exchange.xforce.ibmcloud.com/vulnerabilities/24809