5

CVE-2006-4140

Exploit
Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IpcheckServer Monitor Version4.3.1.368
IpcheckServer Monitor Version4.3.1.382
IpcheckServer Monitor Version4.4.1.521
IpcheckServer Monitor Version4.4.1.522
IpcheckServer Monitor Version5.0.1.272
IpcheckServer Monitor Version5.0.1.299
IpcheckServer Monitor Version5.0.1.309
IpcheckServer Monitor Version5.0.1.321
IpcheckServer Monitor Version5.1.0.341
IpcheckServer Monitor Version5.1.0.342
IpcheckServer Monitor Version5.1.0.345
IpcheckServer Monitor Version5.2.0.404
IpcheckServer Monitor Version5.2.0.405
IpcheckServer Monitor Version5.2.0.418
IpcheckServer Monitor Version5.2.0.420
IpcheckServer Monitor Version5.2.2.449
IpcheckServer Monitor Version5.2.2.451
IpcheckServer Monitor Version5.3.0.506
IpcheckServer Monitor Version5.3.0.507
IpcheckServer Monitor Version5.3.0.508
IpcheckServer Monitor Version5.3.0.509
IpcheckServer Monitor Version5.3.1.574
IpcheckServer Monitor Version5.3.1.575
IpcheckServer Monitor Version5.3.1.578
IpcheckServer Monitor Version5.3.1.579
IpcheckServer Monitor Version5.3.1.580
IpcheckServer Monitor Version5.3.1.581
IpcheckServer Monitor Version5.3.1.586
IpcheckServer Monitor Version5.3.1.587
IpcheckServer Monitor Version5.3.2.605
IpcheckServer Monitor Version5.3.2.606
IpcheckServer Monitor Version5.3.2.609
IpcheckServer Monitor Version5.3.2.610
IpcheckServer Monitor Version5.3.2.616
IpcheckServer Monitor Version5.3.2.617
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 10.88% 0.932
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.