CVE-2006-7103
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a)…
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- ezonlinegallery/ezonlinegallery
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050364.html
- http://securityreason.com/securityalert/2362
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/archive/1/449889/100/0/threaded
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29835
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29836
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050364.html
- http://securityreason.com/securityalert/2362
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/archive/1/449889/100/0/threaded
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29835
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29836
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.