6.4

CVE-2006-1073

Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SimplogSimplog Version <= 1.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.07% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://notlegal.ws/simplogsploit.txt
URL Repurposed
http://www.securityfocus.com/archive/1/426769/100/0/threaded
http://www.securityfocus.com/bid/16965
http://secunia.com/advisories/19115
Vendor Advisory
http://securityreason.com/securityalert/542
http://www.vupen.com/english/advisories/2006/0839
https://exchange.xforce.ibmcloud.com/vulnerabilities/25067