CVE-2006-7103
Last modified
CVE-2006-7103 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in EZOnlineGallery 1.3 and earlier, and possibly other versions before 1.3.2 Beta, allow remote attackers to (1) determine directory existence via a ".." in the album parameter in a show_album action to (a) ezgallery.php, which produces different responses depending on existence; and read arbitrary image files via a ".." in the album or (2) image parameter to (b) image.php.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ezonlinegallery | Ezonlinegallery | 0.9 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.0 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.1 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.2 | Beta |
| Ezonlinegallery | Ezonlinegallery | 1.3 | Beta |
References
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
- http://www.ezonlinegallery.com/changelog.txtURL Repurposed
- http://www.mayhemiclabs.com/advisories/MHL-2006-003.txtExploit, Patch
- http://www.securityfocus.com/bid/20763Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-7103?
How severe is CVE-2006-7103?
How do I fix CVE-2006-7103?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-7097Multiple unspecified vulnerabilities in TaskFreak! before 0.…
- CVE-2006-7098The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache H…
- CVE-2006-7099Directory traversal vulnerability in index.php in SolarPay a…
- CVE-2006-7100PHP remote file inclusion vulnerability in includes/function…
- CVE-2006-7101SQL injection vulnerability in admin.php in PHPWind 5.0.1 an…
- CVE-2006-7102Multiple PHP remote file inclusion vulnerabilities in phpBur…
- CVE-2006-7104PHP remote file inclusion vulnerability in htmltemplate.php …
- CVE-2006-7105PHP remote file inclusion vulnerability in libs/Smarty.class…9.8
- CVE-2006-7106PHP remote file inclusion vulnerability in config.inc.php3 i…
- CVE-2006-7107PHP remote file inclusion vulnerability in upgrade.php in Co…
- CVE-2006-7108login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok…
- CVE-2006-7109Unrestricted file upload vulnerability in IMCE before 1.6, a…
Are you affected by CVE-2006-7103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
