Lucene search

K
cve[email protected]CVE-2006-6376
HistoryDec 07, 2006 - 5:28 p.m.

CVE-2006-6376

2006-12-0717:28:00
web.nvd.nist.gov
19
directory traversal
vulnerabilities
simple file manager
sfm
arbitrary code execution
cve-2006-6376

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.5%

Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use “…” sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.

Affected configurations

NVD
Node
onedotohsimple_file_managerMatch0.24a

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.5%

Related for CVE-2006-6376