CVE Vulnerabilities

CVE-2006-2770

Published: Jun 02, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.4 MEDIUM
AV:N/AC:H/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an index of the file array parameter, as demonstrated by file[0].

Affected Software

Name Vendor Start Version End Version
Pppblog Pppblog * 0.3.8 (including)

References