VulnerabilityModified
CVE-2010-3606
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action…
MEDIUM 6.8EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- netartmedia/real estate portal
- Source
- cve@mitre.org
References
- http://osvdb.org/68062
- http://pridels-team.blogspot.com/2010/09/netartmedia-real-estate-portal-v20-xss.html
- http://secunia.com/advisories/41377Vendor Advisory
- http://www.securityfocus.com/bid/43266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61867
- http://osvdb.org/68062
- http://pridels-team.blogspot.com/2010/09/netartmedia-real-estate-portal-v20-xss.html
- http://secunia.com/advisories/41377Vendor Advisory
- http://www.securityfocus.com/bid/43266
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61867
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.