CVE Vulnerabilities

CVE-2006-6175

Published: Nov 30, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.

Affected Software

NameVendorStart VersionEnd Version
KronolithHorde2.0.1 (including)2.0.1 (including)
KronolithHorde2.0.2 (including)2.0.2 (including)
KronolithHorde2.0.3 (including)2.0.3 (including)
KronolithHorde2.0.4 (including)2.0.4 (including)
KronolithHorde2.0.5 (including)2.0.5 (including)
KronolithHorde2.0.6 (including)2.0.6 (including)
KronolithHorde2.1 (including)2.1 (including)
KronolithHorde2.1.1 (including)2.1.1 (including)
KronolithHorde2.1.2 (including)2.1.2 (including)
KronolithHorde2.1.3 (including)2.1.3 (including)

References