Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2014

Опубликовано: 25 апр. 2006
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:web-provence:sl_site:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 77%
0.0103
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.

EPSS

Процентиль: 77%
0.0103
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other