VulnerabilityModified
CVE-2006-6814
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath…
MEDIUM 6.3EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePath parameter.
- CVSS 2.0
- 6.3 MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- hosting controller/hosting controller
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23585
- http://securitytracker.com/id?1017447Exploit
- http://www.kapda.ir/advisory-458.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/21786Exploit
- http://www.vupen.com/english/advisories/2007/0023
- http://secunia.com/advisories/23585
- http://securitytracker.com/id?1017447Exploit
- http://www.kapda.ir/advisory-458.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/bid/21786Exploit
- http://www.vupen.com/english/advisories/2007/0023
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.