5.1

CVE-2006-1480

Exploit
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DudaWebalbum Version <= 2.02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.21% 0.865
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19400
Vendor Advisory
Exploit
http://www.osvdb.org/24160
http://www.securityfocus.com/bid/17228
Exploit
http://www.vupen.com/english/advisories/2006/1108
https://exchange.xforce.ibmcloud.com/vulnerabilities/25443
https://www.exploit-db.com/exploits/1608