Vulnerabilities > CVE-2006-6877 - Directory Traversal vulnerability in 3Editor Cms

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
matteo-lucarelli
exploit available

Summary

Directory traversal vulnerability in index.php in Matteo Lucarelli 3editor CMS 0.42 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter.

Vulnerable Configurations

Part Description Count
Application
Matteo_Lucarelli
1

Exploit-Db

description3editor CMS <= 0.42 (index.php) Local File Include Vulnerability. CVE-2006-6877. Webapps exploit for php platform
fileexploits/php/webapps/2982.txt
idEDB-ID:2982
last seen2016-01-31
modified2006-12-22
platformphp
port
published2006-12-22
reporter3l3ctric-Cracker
sourcehttps://www.exploit-db.com/download/2982/
title3editor CMS <= 0.42 index.php Local File Include Vulnerability
typewebapps