VulnerabilityModified
CVE-2006-2534
Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.
MEDIUM 5.0EPSS 1.34%
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- greg donald/destiney links script
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/937
- http://www.securityfocus.com/archive/1/434692/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26610
- http://securityreason.com/securityalert/937
- http://www.securityfocus.com/archive/1/434692/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26610
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.