MEDIUM · 5.0

CVE-2006-1995

Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtri...

Vulnerability Description

Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Scry GalleryScry Gallery1.1

References

FAQ

What is CVE-2006-1995?

CVE-2006-1995 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtri...

How severe is CVE-2006-1995?

CVE-2006-1995 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-1995?

Check the references section above for vendor advisories and patch information. Affected products include: Scry Gallery Scry Gallery.