CVE-2006-6514

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flippet.org:winamp_web_interface:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-12-14 01:28

Updated : 2024-02-04 17:13


NVD link : CVE-2006-6514

Mitre link : CVE-2006-6514

CVE.ORG link : CVE-2006-6514


JSON object : View

Products Affected

flippet.org

  • winamp_web_interface