7.5

CVE-2006-6175

Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.

Data is provided by the National Vulnerability Database (NVD)
HordeKronolith Version2.0.1
HordeKronolith Version2.0.2
HordeKronolith Version2.0.3
HordeKronolith Version2.0.4
HordeKronolith Version2.0.5
HordeKronolith Version2.0.6
HordeKronolith Version2.1
HordeKronolith Version2.1.1
HordeKronolith Version2.1.2
HordeKronolith Version2.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.89% 0.824
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P