7.8
CVSSv2

CVE-2006-2690

Published: 31/05/2006 Updated: 09/11/2008
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

An unspecified script in EVA-Web 2.1.2 and previous versions, probably index.php, allows remote malicious users to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

eva-web eva-web