Vulnerabilities > CVE-2006-4490 - Directory Traversal vulnerability in Cybozu Office

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cybozu
exploit available

Summary

Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe.

Vulnerable Configurations

Part Description Count
Application
Cybozu
2

Exploit-Db

descriptionCybozu Products (id) Arbitrary File Retrieval Vulnerability. CVE-2006-4490. Webapps exploit for cgi platform
idEDB-ID:2266
last seen2016-01-31
modified2006-08-28
published2006-08-28
reporterTan Chew Keong
sourcehttps://www.exploit-db.com/download/2266/
titleCybozu Products id Arbitrary File Retrieval Vulnerability