Lucene search

K
cveMitreCVE-2006-5705
HistoryNov 04, 2006 - 1:07 a.m.

CVE-2006-5705

2006-11-0401:07:00
mitre
web.nvd.nist.gov
27
cve
2006
5705
directory traversal
wordpress
vulnerability
nvd

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

71.6%

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters in a GET request.

Affected configurations

Nvd
Node
wordpresswordpressRange2.0.4
OR
wordpresswordpressMatch2.0.2
OR
wordpresswordpressMatch2.0.3
VendorProductVersionCPE
wordpresswordpress2.0.3cpe:/a:wordpress:wordpress:2.0.3:::
wordpresswordpresscpe:/a:wordpress:wordpress::::
wordpresswordpress2.0.2cpe:/a:wordpress:wordpress:2.0.2:::

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

71.6%