Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2014

Опубликовано: 25 апр. 2006
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:web-provence:sl_site:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01932
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 4 лет назад

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

EPSS

Процентиль: 79%
0.01932
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other