← back
CVE-2006-0244

CVE-2006-0244

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 3.1%
from disclosure to weapon0 days
Published on NVDJan 18
1st PoCJan 16
exploitation probability
3.1%top 13% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.