5.1
CVE-2006-1480
- EPSS 3.21%
- Veröffentlicht 29.03.2006 01:06:00
- Zuletzt bearbeitet 16.06.2026 22:22:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.21% | 0.865 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/19400
http://www.osvdb.org/24160
http://www.securityfocus.com/bid/17228
http://www.vupen.com/english/advisories/2006/1108
https://exchange.xforce.ibmcloud.com/vulnerabilities/25443
https://www.exploit-db.com/exploits/1608