Vulnerabilities > CVE-2006-0660 - Directory Traversal and Local File Include vulnerability in Farsinews 2.1/2.1Beta2/2.5

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
farsinews
exploit available

Summary

Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.

Vulnerable Configurations

Part Description Count
Application
Farsinews
3

Exploit-Db

  • descriptionFarsiNews <= 2.5 Directory Traversal Arbitrary (users.db) Access Exploit. CVE-2006-0660. Webapps exploit for php platform
    idEDB-ID:1538
    last seen2016-01-31
    modified2006-02-28
    published2006-02-28
    reporterHessam-x
    sourcehttps://www.exploit-db.com/download/1538/
    titlefarsinews <= 2.5 - Directory Traversal arbitrary users.db access Exploit
  • descriptionFarsiNews 2.1/2.5 show_archives.php template Parameter Traversal Arbitrary File Access. CVE-2006-0660. Webapps exploit for php platform
    idEDB-ID:27183
    last seen2016-02-03
    modified2006-02-10
    published2006-02-10
    reporterHamid Ebadi
    sourcehttps://www.exploit-db.com/download/27183/
    titleFarsiNews 2.1/2.5 show_archives.php template Parameter Traversal Arbitrary File Access