Vulnerabilities > CVE-2006-6257 - Input Validation vulnerability in AlternC

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
alternc

Summary

The file manager in AlternC 0.9.5 and earlier, when warnings are enabled in PHP, allows remote attackers to obtain sensitive information via certain folder names such as ones composed of JavaScript code, which reveal the path in a warning message. Successful exploitation requires that warnings are enabled in PHP.

Vulnerable Configurations

Part Description Count
Application
Alternc
1