Vulnerability CVE-2006-0132


Published: 2006-01-09   Modified: 2012-02-12

Description:
Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Webftp -> Webftp 

 References:
http://www.securityfocus.com/archive/1/420973/100/0/threaded
http://www.securityfocus.com/bid/16175
http://www.vupen.com/english/advisories/2006/0090
https://exchange.xforce.ibmcloud.com/vulnerabilities/24018

Copyright 2024, cxsecurity.com

 

Back to Top