7.8

CVE-2006-3534

Exploit
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing "/content".
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NullsoftShoutcast Server Version <= 1.9.5
NullsoftShoutcast Server Version1.7.1 Editionlinux
NullsoftShoutcast Server Version1.8.2
NullsoftShoutcast Server Version1.8.3
NullsoftShoutcast Server Version1.8.3 Editionwin32
NullsoftShoutcast Server Version1.8.9
NullsoftShoutcast Server Version1.8.9 Editionfreebsd
NullsoftShoutcast Server Version1.8.9 Editionlinux
NullsoftShoutcast Server Version1.8.9 Editionmac_os_x
NullsoftShoutcast Server Version1.8.9 Editionsolaris
NullsoftShoutcast Server Version1.8.9 Editionwin32
NullsoftShoutcast Server Version1.9.2
NullsoftShoutcast Server Version1.9.2 Editionwin32
NullsoftShoutcast Server Version1.9.4 Editionlinux
NullsoftShoutcast Server Version1.9.4 Editionmac_os_x
NullsoftShoutcast Server Version1.9.4 Editionwin32
NullsoftShoutcast Server Version1.9.5 Editionlinux
NullsoftShoutcast Server Version1.9.5 Editionmac_os_x
NullsoftShoutcast Server Version1.9.5 Editionwin32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.785
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:C/I:N/A:N