Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6514

Опубликовано: 14 дек. 2006
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flippet.org:winamp_web_interface:*:*:*:*:*:*:*:*
Версия до 7.5.13 (включая)

EPSS

Процентиль: 73%
0.00749
Низкий

3.5 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

EPSS

Процентиль: 73%
0.00749
Низкий

3.5 Low

CVSS2

Дефекты

NVD-CWE-Other