5
CVSSv2

CVE-2006-6938

Published: 17/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed prior to 2006, allows remote malicious users to include arbitrary files via ".." sequences in the root parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

nitrotech nitrotech 0.0.3a

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print ' ::::::::: :::::::::: ::: ::: ::::::::::: ::: :+: :+: :+: :+: :+: :+: :+: +:+ +:+ +:+ +:+ +:+ +:+ +:+ +#+ +:+ +#++:++# +#+ +:+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ #+# ...