7.5
CVSSv2

CVE-2006-1771

Published: 13/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in misc in pbcs.dll in SAXoTECH SAXoPRESS, aka Saxotech Online (formerly Publicus) allows remote malicious users to read arbitrary files and possibly execute arbitrary programs via a .. (dot dot) in the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

saxotech saxopress

Exploits

source: wwwsecurityfocuscom/bid/17474/info SAXoPRESS is prone to a directory-traversal vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve and execute arbitrary files from the vulnerable system in the context of the affected app ...