Vulnerabilities > CVE-2006-5498 - Unspecified vulnerability in Middlebury College Segue CMS
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://sourceforge.net/forum/forum.php?forum_id=625467
- http://sourceforge.net/forum/forum.php?forum_id=625467
- http://www.vupen.com/english/advisories/2006/4122
- http://www.vupen.com/english/advisories/2006/4122
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29692
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29692