Vulnerabilities > CVE-2006-3050 - Directory Traversal vulnerability in SixCMS
Attack vector
NETWORK Attack complexity
HIGH Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | SixCMS 6.0 Detail.PHP Directory Traversal Vulnerability. CVE-2006-3050. Webapps exploit for php platform |
id | EDB-ID:28014 |
last seen | 2016-02-03 |
modified | 2006-06-12 |
published | 2006-06-12 |
reporter | Aesthetico |
source | https://www.exploit-db.com/download/28014/ |
title | SixCMS 6.0 Detail.PHP Directory Traversal Vulnerability |
References
- http://securityreason.com/securityalert/1101
- http://securitytracker.com/id?1016282
- http://www.majorsecurity.de/advisory/major_rls17.txt
- http://www.securityfocus.com/archive/1/437047/100/0/threaded
- http://www.securityfocus.com/archive/1/437639/100/0/threaded
- http://www.securityfocus.com/bid/18395
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27107