CVE Vulnerabilities

CVE-2006-1201

Published: Mar 14, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a Recover password operation (recoverpw.php).

Affected Software

NameVendorStart VersionEnd Version
PhpbannerexchangeEschew.net2.0 (including)2.0 (including)
PhpbannerexchangeEschew.net2.0_update_1 (including)2.0_update_1 (including)
PhpbannerexchangeEschew.net2.0_update_2 (including)2.0_update_2 (including)
PhpbannerexchangeEschew.net2.0_update_3 (including)2.0_update_3 (including)
PhpbannerexchangeEschew.net2.0_update_4 (including)2.0_update_4 (including)

References