Vulnerabilities > CVE-2006-4651 - Unspecified vulnerability in Threesquared.Net PHP Download Script
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in download/index.php, and possibly download.php, in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via .. (dot dot) sequence in the file parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://secunia.com/advisories/21774
- http://secunia.com/advisories/21774
- http://securityreason.com/securityalert/1528
- http://securityreason.com/securityalert/1528
- http://www.securityfocus.com/archive/1/445269/100/0/threaded
- http://www.securityfocus.com/archive/1/445269/100/0/threaded
- http://www.securityfocus.com/bid/19872
- http://www.securityfocus.com/bid/19872
- http://www.vupen.com/english/advisories/2006/3479
- http://www.vupen.com/english/advisories/2006/3479
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28751
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28751