CVE-2006-4651 Information
Feb 14, 2021
cve
Description
Directory traversal vulnerability in download/index.php and possibly download.php in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via .. (dot dot) sequence in the file parameter.
Reference
http://secunia.com/advisories/21774 http://securityreason.com/securityalert/1528 http://www.securityfocus.com/archive/1/445269/100/0/threaded http://www.securityfocus.com/bid/19872 http://www.vupen.com/english/advisories/2006/3479 https://exchange.xforce.ibmcloud.com/vulnerabilities/28751
Share on: