5.1
CVSSv2

CVE-2006-1162

Published: 12/03/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in Nodez 4.6.1.1 and previous versions allows remote malicious users to read or include arbitrary PHP files via a .. (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nodez nodez 4.6.1.1

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "Nodez 4611 Mercury (possibly prior versions) multiple vulnerabilities\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; /* software: site: nodezgreentintedcom/ description: Nodez - "An open source (content management system), designed ...