5
CVSSv2

CVE-2006-0244

Published: 18/01/2006 Updated: 17/05/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote malicious users to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root

Vulnerable Product Search on Vulmon Subscribe to Product

phpxplorer phpxplorer 0.9.33

Exploits

source: wwwsecurityfocuscom/bid/16263/info phpXplorer is prone to a directory traversal vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the Web server process Info ...