CVE-2006-0434
Last modified
CVE-2006-0434 is a vulnerability of currently unknown severity. Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244. NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.. EPSS estimates a 1.76% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244. NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpxplorer | Phpxplorer | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0434?
How severe is CVE-2006-0434?
How do I fix CVE-2006-0434?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-0428Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 thr…
- CVE-2006-0429BEA WebLogic Server and WebLogic Express 9.0 causes new secu…
- CVE-2006-0430Certain configurations of BEA WebLogic Server and WebLogic E…
- CVE-2006-0431Unspecified vulnerability in BEA WebLogic Server and WebLogi…
- CVE-2006-0432Unspecified vulnerability in BEA WebLogic Server and WebLogi…
- CVE-2006-0433Selective Acknowledgement (SACK) in FreeBSD 5.3 and 5.4 does…
- CVE-2006-0435Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used …
- CVE-2006-0436Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and …
- CVE-2006-0437Cross-site scripting (XSS) vulnerability in admin_smilies.ph…
- CVE-2006-0438Cross-site request forgery (CSRF) vulnerability in phpBB 2.0…
- CVE-2006-0439Text Rider 2.4 stores sensitive data in the data directory u…
- CVE-2006-0440Text Rider 2.4 allows attackers to bypass authentication and…
Are you affected by CVE-2006-0434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
