Vulnerabilities > CVE-2006-3050 - Directory Traversal vulnerability in SixCMS

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
high complexity
six-offene-systeme-gmbh
exploit available

Summary

Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.

Vulnerable Configurations

Part Description Count
Application
Six_Offene_Systeme_Gmbh
1

Exploit-Db

descriptionSixCMS 6.0 Detail.PHP Directory Traversal Vulnerability. CVE-2006-3050. Webapps exploit for php platform
idEDB-ID:28014
last seen2016-02-03
modified2006-06-12
published2006-06-12
reporterAesthetico
sourcehttps://www.exploit-db.com/download/28014/
titleSixCMS 6.0 Detail.PHP Directory Traversal Vulnerability