5

CVE-2006-2347

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories.  NOTE: this issue might be resultant from SQL injection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OasyssoftE-business Designer Version <= 3.1.4
OasyssoftE-business Designer Version2.3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.679
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/045980.html
Vendor Advisory
http://secunia.com/advisories/20071
Vendor Advisory
http://securityreason.com/securityalert/891
http://www.securityfocus.com/archive/1/433807/100/0/threaded
http://www.securityfocus.com/bid/17933
http://www.vupen.com/english/advisories/2006/1784
https://exchange.xforce.ibmcloud.com/vulnerabilities/26476