VulnerabilityModified
CVE-2006-1175
SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.
MEDIUM 4.0EPSS 2.33%
Does this matter?
Lower severity and a low EPSS score (2.33%). Track it; it rarely justifies an emergency change on its own.
Description
The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- weonlydo/weonlydo sftp
- Source
- cret@cert.org
References
- http://secunia.com/advisories/20361
- http://www.kb.cert.org/vuls/id/378604US Government Resource
- http://www.securityfocus.com/bid/18192
- http://www.vupen.com/english/advisories/2006/2064
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26752
- http://secunia.com/advisories/20361
- http://www.kb.cert.org/vuls/id/378604US Government Resource
- http://www.securityfocus.com/bid/18192
- http://www.vupen.com/english/advisories/2006/2064
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26752
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.