6.4
CVSSv2

CVE-2006-3194

Published: 23/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php in singapore 0.10.0 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) gallery and (2) template parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

singapore singapore 0.9.3_beta

singapore singapore 0.9.4_beta

singapore singapore 0.9.9b_beta

singapore singapore 0.9_beta

singapore singapore 0.9a_beta

singapore singapore 0.9.11_beta

singapore singapore 0.9.2_beta

singapore singapore 0.9.8_beta

singapore singapore 0.9.9a_beta

singapore singapore 0.10.0

singapore singapore 0.9.1_beta

singapore singapore 0.9.5_beta

singapore singapore 0.9.6_beta

singapore singapore 0.9.10

singapore singapore 0.9.10_beta

singapore singapore 0.9.7

singapore singapore 0.9.7_beta

Exploits

source: wwwsecurityfocuscom/bid/18518/info singapore gallery is prone to directory-traversal and cross-site scripting vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit the directory-traversal vulnerabilities to retrieve arbitrary files from the vulnera ...