5
CVSSv2

CVE-2006-6277

Published: 04/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in admin/FileServer.php in ContentServ 4.x allows remote malicious users to read arbitrary files via a .. (dot dot) in the src parameter, a different vector than CVE-2005-3086.

Vulnerable Product Search on Vulmon Subscribe to Product

contentserv contentserv 4.0

contentserv contentserv 4.1

Exploits

ContentServ again (still) features remote reading of arbitrary files ==================================================================== ContentServ is a cms and "cross media publishing" software Let me quote from their website: "At ContentServ, there is always something happening We continously enhance our products and services[]" Ok ...