5

CVE-2006-1995

Exploit
Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Scry GalleryScry Gallery Version1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.38% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://attrition.org/pipermail/vim/2006-April/000716.html
http://downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploit
Exploit
http://secunia.com/advisories/19777
http://securityreason.com/securityalert/784
http://www.osvdb.org/24889
http://www.securityfocus.com/archive/1/431716/100/0/threaded
http://www.securityfocus.com/bid/17649
Exploit
http://www.securityfocus.com/bid/17668
http://www.vupen.com/english/advisories/2006/1490
https://exchange.xforce.ibmcloud.com/vulnerabilities/25991