Lucene search

K
cve[email protected]CVE-2006-6242
HistoryDec 03, 2006 - 7:28 p.m.

CVE-2006-6242

2006-12-0319:28:00
CWE-22
web.nvd.nist.gov
27
cve
2006
6242
directory traversal
vulnerability
serendipity
remote attackers
arbitrary local files
security
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.033 Low

EPSS

Percentile

91.3%

Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a … (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins/ scripts (2) serendipity_event_bbcode/serendipity_event_bbcode.php, (3) serendipity_event_browsercompatibility/serendipity_event_browsercompatibility.php, (4) serendipity_event_contentrewrite/serendipity_event_contentrewrite.php, (5) serendipity_event_creativecommons/serendipity_event_creativecommons.php, (6) serendipity_event_emoticate/serendipity_event_emoticate.php, (7) serendipity_event_entryproperties/serendipity_event_entryproperties.php, (8) serendipity_event_karma/serendipity_event_karma.php, (9) serendipity_event_livesearch/serendipity_event_livesearch.php, (10) serendipity_event_mailer/serendipity_event_mailer.php, (11) serendipity_event_nl2br/serendipity_event_nl2br.php, (12) serendipity_event_s9ymarkup/serendipity_event_s9ymarkup.php, (13) serendipity_event_searchhighlight/serendipity_event_searchhighlight.php, (14) serendipity_event_spamblock/serendipity_event_spamblock.php, (15) serendipity_event_spartacus/serendipity_event_spartacus.php, (16) serendipity_event_statistics/serendipity_plugin_statistics.php, (17) serendipity_event_templatechooser/serendipity_event_templatechooser.php, (18) serendipity_event_textile/serendipity_event_textile.php, (19) serendipity_event_textwiki/serendipity_event_textwiki.php, (20) serendipity_event_trackexits/serendipity_event_trackexits.php, (21) serendipity_event_weblogping/serendipity_event_weblogping.php, (22) serendipity_event_xhtmlcleanup/serendipity_event_xhtmlcleanup.php, (23) serendipity_plugin_comments/serendipity_plugin_comments.php, (24) serendipity_plugin_creativecommons/serendipity_plugin_creativecommons.php, (25) serendipity_plugin_entrylinks/serendipity_plugin_entrylinks.php, (26) serendipity_plugin_eventwrapper/serendipity_plugin_eventwrapper.php, (27) serendipity_plugin_history/serendipity_plugin_history.php, (28) serendipity_plugin_recententries/serendipity_plugin_recententries.php, (29) serendipity_plugin_remoterss/serendipity_plugin_remoterss.php, (30) serendipity_plugin_shoutbox/serendipity_plugin_shoutbox.php, and and (31) serendipity_plugin_templatedropdown/serendipity_plugin_templatedropdown.php.

Affected configurations

NVD
Node
s9yserendipityMatch0.3
OR
s9yserendipityMatch0.4
OR
s9yserendipityMatch0.5
OR
s9yserendipityMatch0.5_pl1
OR
s9yserendipityMatch0.6
OR
s9yserendipityMatch0.6_pl1
OR
s9yserendipityMatch0.6_pl2
OR
s9yserendipityMatch0.6_pl3
OR
s9yserendipityMatch0.6_rc1
OR
s9yserendipityMatch0.6_rc2
OR
s9yserendipityMatch0.7
OR
s9yserendipityMatch0.7.1
OR
s9yserendipityMatch0.7_beta1
OR
s9yserendipityMatch0.7_beta2
OR
s9yserendipityMatch0.7_beta3
OR
s9yserendipityMatch0.7_beta4
OR
s9yserendipityMatch0.7_rc1
OR
s9yserendipityMatch0.8
OR
s9yserendipityMatch0.8.1
OR
s9yserendipityMatch0.8.2
OR
s9yserendipityMatch0.8_beta5
OR
s9yserendipityMatch0.8_beta6
OR
s9yserendipityMatch0.9.1
OR
s9yserendipityMatch1.0.3
OR
s9yserendipityMatch1.0_beta2
OR
s9yserendipityMatch1.0_beta3

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.033 Low

EPSS

Percentile

91.3%

Related for CVE-2006-6242