Описание
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-3050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27107
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282
- http://www.majorsecurity.de/advisory/major_rls17.txt
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18395
EPSS
Процентиль: 90%
0.05605
Низкий
CVE ID
Связанные уязвимости
nvd
больше 19 лет назад
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
EPSS
Процентиль: 90%
0.05605
Низкий