Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-3426

Опубликовано: 07 июл. 2006
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.181:*:*:*:*:*:*:*
cpe:2.3:a:lumension:patchlink_update_server:6.2.0.189:*:*:*:*:*:*:*
cpe:2.3:a:novell:zenworks:*:sr1:*:*:*:*:*:*
Версия до 6.2 (включая)

EPSS

Процентиль: 84%
0.02626
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
около 4 лет назад

Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.

EPSS

Процентиль: 84%
0.02626
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other