6.4

CVE-2006-7103

Exploit
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EzonlinegalleryEzonlinegallery Version0.9 Updatebeta
EzonlinegalleryEzonlinegallery Version1.0 Updatebeta
EzonlinegalleryEzonlinegallery Version1.1 Updatebeta
EzonlinegalleryEzonlinegallery Version1.2 Updatebeta
EzonlinegalleryEzonlinegallery Version1.3 Updatebeta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.86% 0.765
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050364.html
http://securityreason.com/securityalert/2362
http://www.ezonlinegallery.com/changelog.txt
URL Repurposed
http://www.mayhemiclabs.com/advisories/MHL-2006-003.txt
Patch
Exploit
http://www.securityfocus.com/archive/1/449889/100/0/threaded
http://www.securityfocus.com/bid/20763
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/29835
https://exchange.xforce.ibmcloud.com/vulnerabilities/29836