VulnerabilityModified
CVE-2006-3050
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a ..
LOW 2.6EPSS 3.11%
Does this matter?
Lower severity and a low EPSS score (3.11%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
- EPSS
- 3.11% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- six offene systeme gmbh/sixcms
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282Exploit
- http://www.majorsecurity.de/advisory/major_rls17.txtExploit
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18395Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27107
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282Exploit
- http://www.majorsecurity.de/advisory/major_rls17.txtExploit
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18395Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27107
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.