Vulnerabilities > CVE-2006-4161 - Directory Traversal vulnerability in XennoBB
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |
Exploit-Db
description | XennoBB 1.0.5/1.0.6/2.1/2.2 Profile.PHP Directory Traversal Vulnerability. CVE-2006-4161. Webapps exploit for php platform |
id | EDB-ID:28364 |
last seen | 2016-02-03 |
modified | 2006-08-09 |
published | 2006-08-09 |
reporter | Chris Boulton |
source | https://www.exploit-db.com/download/28364/ |
title | XennoBB 1.0.5/1.0.6/2.1/2.2 Profile.PHP Directory Traversal Vulnerability |
References
- http://secunia.com/advisories/21483
- http://securityreason.com/securityalert/1395
- http://www.securityfocus.com/archive/1/442881/100/0/threaded
- http://www.securityfocus.com/bid/19446
- http://www.surfionline.com/security_advisories/20060810_xennobb_avatar_gallery_transversal.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28337