CVE Vulnerabilities

CVE-2006-2690

Published: May 31, 2006 | Modified: Nov 09, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An unspecified script in EVA-Web 2.1.2 and earlier, probably index.php, allows remote attackers to obtain the full path of the web server via invalid (1) perso or (2) aide parameters.

Affected Software

Name Vendor Start Version End Version
Eva-web Eva-web * 2.1.2 (including)

References