CVE-2006-0847 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ..\ sequences in unspecified vectors.
Reference
http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc3062f63afc9433dc306 http://secunia.com/advisories/18944 http://secunia.com/advisories/20344 http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099 http://www.cherrypy.org/ http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml http://www.securityfocus.com/bid/16760 http://www.vupen.com/english/advisories/2006/0677 https://exchange.xforce.ibmcloud.com/vulnerabilities/24809
Share on: