CVE-2006-2014

Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:web-provence:sl_site:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-04-25 12:50

Updated : 2024-02-04 16:52


NVD link : CVE-2006-2014

Mitre link : CVE-2006-2014

CVE.ORG link : CVE-2006-2014


JSON object : View

Products Affected

web-provence

  • sl_site