5

CVE-2006-2658

Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.

Data is provided by the National Vulnerability Database (NVD)
MonoXsp
SuseSuse Linux Version9.2 Editionpersonal
SuseSuse Linux Version9.2 Editionprofessional
SuseSuse Linux Version9.2 Editionx86_64
SuseSuse Linux Version9.3 Editionpersonal
SuseSuse Linux Version9.3 Editionprofessional
SuseSuse Linux Version9.3 Editionx86_64
SuseSuse Linux Version10.0 Editionoss
SuseSuse Linux Version10.0 Editionprofessional
SuseSuse Linux Version10.1 Editionpersonal
SuseSuse Linux Version10.1 Editionprofessional
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.67% 0.704
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N