Vulnerabilities > CVE-2006-4766 - Directory Traversal vulnerability in Stefan Ernst Newsscript 0.5Beta

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
stefan-ernst
exploit available

Summary

Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a .. (dot dot) in the ide parameter.

Vulnerable Configurations

Part Description Count
Application
Stefan_Ernst
1

Exploit-Db

descriptionNewsscript <= 0.5 Remote and Local File Include Vulnerability. CVE-2006-4766. Webapps exploit for php platform
idEDB-ID:2365
last seen2016-01-31
modified2006-09-13
published2006-09-13
reporterDaftrix Security
sourcehttps://www.exploit-db.com/download/2365/
titleNewsscript <= 0.5 - Remote and Local File Include Vulnerability