CVE Vulnerabilities

CVE-2006-6175

Published: Nov 30, 2006 | Modified: Oct 18, 2016
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.

Affected Software

Name Vendor Start Version End Version
Kronolith Horde 2.0.1 (including) 2.0.1 (including)
Kronolith Horde 2.0.2 (including) 2.0.2 (including)
Kronolith Horde 2.0.3 (including) 2.0.3 (including)
Kronolith Horde 2.0.4 (including) 2.0.4 (including)
Kronolith Horde 2.0.5 (including) 2.0.5 (including)
Kronolith Horde 2.0.6 (including) 2.0.6 (including)
Kronolith Horde 2.1 (including) 2.1 (including)
Kronolith Horde 2.1.1 (including) 2.1.1 (including)
Kronolith Horde 2.1.2 (including) 2.1.2 (including)
Kronolith Horde 2.1.3 (including) 2.1.3 (including)

References