Vulnerability Description
Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded .. (dot dot) in the URL on TCP port 18264.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Firewall-1 | r55w |
References
- http://secunia.com/advisories/21200
- http://securityreason.com/securityalert/1290
- http://securitytracker.com/id?1016563
- http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html
- http://www.securityfocus.com/archive/1/440990/100/0/threaded
- http://www.securityfocus.com/archive/1/441495/100/0/threaded
- http://www.securityfocus.com/bid/19136ExploitPatch
- http://www.vupen.com/english/advisories/2006/2965
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27937
- http://secunia.com/advisories/21200
- http://securityreason.com/securityalert/1290
- http://securitytracker.com/id?1016563
- http://www.sec-tec.co.uk/vulnerability/r55w_directory_traversal.html
- http://www.securityfocus.com/archive/1/440990/100/0/threaded
- http://www.securityfocus.com/archive/1/441495/100/0/threaded
FAQ
What is CVE-2006-3885?
CVE-2006-3885 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded .. (dot dot) in the URL on TCP port 18264.
How severe is CVE-2006-3885?
CVE-2006-3885 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-3885?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Firewall-1.