CVE-2006-4140
Last modified
CVE-2006-4140 is a vulnerability of currently unknown severity. Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash).. EPSS estimates a 4.16% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash).
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ipcheck | Server Monitor | 4.3.1.368 |
| Ipcheck | Server Monitor | 4.3.1.382 |
| Ipcheck | Server Monitor | 4.4.1.521 |
| Ipcheck | Server Monitor | 4.4.1.522 |
| Ipcheck | Server Monitor | 5.0.1.272 |
| Ipcheck | Server Monitor | 5.0.1.299 |
| Ipcheck | Server Monitor | 5.0.1.309 |
| Ipcheck | Server Monitor | 5.0.1.321 |
| Ipcheck | Server Monitor | 5.1.0.341 |
| Ipcheck | Server Monitor | 5.1.0.342 |
| Ipcheck | Server Monitor | 5.1.0.345 |
| Ipcheck | Server Monitor | 5.2.0.404 |
| Ipcheck | Server Monitor | 5.2.0.405 |
| Ipcheck | Server Monitor | 5.2.0.418 |
| Ipcheck | Server Monitor | 5.2.0.420 |
| Ipcheck | Server Monitor | 5.2.2.449 |
| Ipcheck | Server Monitor | 5.2.2.451 |
| Ipcheck | Server Monitor | 5.3.0.506 |
| Ipcheck | Server Monitor | 5.3.0.507 |
| Ipcheck | Server Monitor | 5.3.0.508 |
| Ipcheck | Server Monitor | 5.3.0.509 |
| Ipcheck | Server Monitor | 5.3.1.574 |
| Ipcheck | Server Monitor | 5.3.1.575 |
| Ipcheck | Server Monitor | 5.3.1.578 |
| Ipcheck | Server Monitor | 5.3.1.579 |
| Ipcheck | Server Monitor | 5.3.1.580 |
| Ipcheck | Server Monitor | 5.3.1.581 |
| Ipcheck | Server Monitor | 5.3.1.586 |
| Ipcheck | Server Monitor | 5.3.1.587 |
| Ipcheck | Server Monitor | 5.3.2.605 |
| Ipcheck | Server Monitor | 5.3.2.606 |
| Ipcheck | Server Monitor | 5.3.2.609 |
| Ipcheck | Server Monitor | 5.3.2.610 |
| Ipcheck | Server Monitor | 5.3.2.616 |
| Ipcheck | Server Monitor | 5.3.2.617 |
References
- http://secunia.com/advisories/21468Exploit, Vendor Advisory
- http://secunia.com/advisories/21468Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4140?
How severe is CVE-2006-4140?
How do I fix CVE-2006-4140?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-4134Unspecified vulnerability related to a "design flaw" in SAP …
- CVE-2006-4135PHP remote file inclusion vulnerability in cal_config.inc.ph…
- CVE-2006-4136Multiple unspecified vulnerabilities in IBM WebSphere Applic…
- CVE-2006-4137IBM WebSphere Application Server before 6.1.0.1 allows attac…
- CVE-2006-4138Multiple unspecified vulnerabilities in Microsoft Windows He…
- CVE-2006-4139Race condition in Sun Solaris 10 allows attackers to cause a…
- CVE-2006-4141SQL injection vulnerability in news.php in Virtual War (VWar…
- CVE-2006-4142SQL injection vulnerability in extra/online.php in Virtual W…
- CVE-2006-4143Netgear FVG318 running firmware 1.0.40 allows remote attacke…
- CVE-2006-4144Integer overflow in the ReadSGIImage function in sgi.c in Im…
- CVE-2006-4145The Universal Disk Format (UDF) filesystem driver in Linux k…
- CVE-2006-4146Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF…
Are you affected by CVE-2006-4140?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
