LOW · 3.5

CVE-2006-6514

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated use...

Vulnerability Description

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

CVSS Score

3.5

LOW

AV:N/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Flippet.OrgWinamp Web Interface<= 7.5.13

References

FAQ

What is CVE-2006-6514?

CVE-2006-6514 is a vulnerability with a CVSS score of 3.5 (LOW). Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated use...

How severe is CVE-2006-6514?

CVE-2006-6514 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6514?

Check the references section above for vendor advisories and patch information. Affected products include: Flippet.Org Winamp Web Interface.