5
CVSSv2

CVE-2006-4161

Published: 16/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and previous versions allows remote malicious users to read arbitrary files via a .. (dot dot) in the category parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

xennobb xennobb 1.0.3

xennobb xennobb 1.0.4

xennobb xennobb 1.0

xennobb xennobb 1.0.1

xennobb xennobb 1.0.2

xennobb xennobb 1.0.5

xennobb xennobb

Exploits

source: wwwsecurityfocuscom/bid/19446/info XennoBB is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application Information obtained may aid in furthe ...