7.5
CVSSv2

CVE-2006-0899

Published: 27/02/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in index.php in 4Images 1.7.1 and previous versions allows remote malicious users to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

4images image gallery management system

Exploits

<?php # ----4images_171_incl_xplphp 645 26/02/2006 # # # # 4Images <= 171 remote commands execution through arbitrary local # # inclusion # # ...