CVE-2006-7103
Last modified
CVE-2006-7103 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ezonlinegallery | Ezonlinegallery | 0.9 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.0 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.1 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.2 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.3 | Beta |
References
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-7103?
How severe is CVE-2006-7103?
How do I fix CVE-2006-7103?
Are you affected by CVE-2006-7103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
