CVE-2006-1480
N/A
N/A
Summary
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.osvdb.org/24160
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25443
- http://secunia.com/advisories/19400
- http://www.securityfocus.com/bid/17228
- http://www.vupen.com/english/advisories/2006/1108
- https://www.exploit-db.com/exploits/1608
References
- http://www.osvdb.org/24160
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25443
- http://secunia.com/advisories/19400
- http://www.securityfocus.com/bid/17228
- http://www.vupen.com/english/advisories/2006/1108
- https://www.exploit-db.com/exploits/1608
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.