VDB
CVE-2006-6175
CVE-2006-6175
PUBLISHED
CVSS 7.5 HIGH
Directory traversal vulnerability in lib/FBView.php in Horde Kronolith H3 before 2.0.7 and 2.1.x before 2.1.4 allows remote attackers to include arbitrary files and execute PHP code via a .. (dot dot) sequence in the view parameter.
EPSS 1.92% · 83.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
1.92%
83.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| horde | kronolith | 2.0.5, 2.0.1, 2.0.2 |
| n/a | n/a | n/a |
Timeline
- Nov 30, 2006 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 21341 vdb
- 1017316 vdb
- ADV-2006-4775 vdb
- [horde-announce] 20061129 [SECURITY] Kronolith H3 (2.0.7) (final) mailing-list
- 23145 third-party-advisory
- 20061129 Horde Kronolith Arbitrary Local File Inclusion Vulnerability third-party-advisory
- [horde-announce] 20061129 [SECURITY] Kronolith H3 (2.1.4) (final) mailing-list
- GLSA-200701-11 vendor-advisory
- 23780 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2006-6175 advisory