Vulnerabilities > CVE-2006-6514 - Unspecified vulnerability in Flippet.Org Winamp web Interface
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://aluigi.altervista.org/adv/wawix-adv.txt
- http://aluigi.altervista.org/adv/wawix-adv.txt
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051217.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-December/051217.html
- http://secunia.com/advisories/23292
- http://secunia.com/advisories/23292
- http://securityreason.com/securityalert/2032
- http://securityreason.com/securityalert/2032
- http://securitytracker.com/id?1017362
- http://securitytracker.com/id?1017362
- http://www.securityfocus.com/archive/1/454059/100/0/threaded
- http://www.securityfocus.com/archive/1/454059/100/0/threaded
- http://www.securityfocus.com/bid/21539
- http://www.securityfocus.com/bid/21539
- http://www.vupen.com/english/advisories/2006/4935
- http://www.vupen.com/english/advisories/2006/4935
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30830
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30830