5
CVE-2006-7133
- EPSS 2.76%
- Veröffentlicht 06.03.2007 01:19:00
- Zuletzt bearbeitet 16.06.2026 22:34:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php Upload Tool ≫ Php Upload Tool Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.76% | 0.843 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://secunia.com/advisories/22973
http://www.craigheffner.com/security/exploits/upload_tool_php.txt
http://www.securityfocus.com/bid/21150
http://www.vupen.com/english/advisories/2006/4575
https://exchange.xforce.ibmcloud.com/vulnerabilities/30322