Vulnerabilities > CVE-2006-1995 - Directory Traversal vulnerability in Scry Gallery Scry Gallery 1.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
scry-gallery
exploit available

Summary

Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.

Vulnerable Configurations

Part Description Count
Application
Scry_Gallery
1

Exploit-Db

descriptionScry Gallery Directory Traversal Vulnerability. CVE-2006-1995. Webapps exploit for php platform
idEDB-ID:27724
last seen2016-02-03
modified2006-04-21
published2006-04-21
reporterMorocco Security Team
sourcehttps://www.exploit-db.com/download/27724/
titleScry Gallery Directory Traversal Vulnerability