PT-2006-1174 · Idv · Idv Directory Viewer

Published

2006-01-05

·

Updated

2011-03-08

·

CVE-2006-0090

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: IDV Directory Viewer versions prior to 2005.1
Description: The issue allows remote attackers to view arbitrary directory contents. This is achieved by using a .. (dot dot) in the dir parameter of the index.php file, enabling directory traversal.
Recommendations: For versions prior to 2005.1, update to version 2005.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the index.php file or disabling the dir parameter to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0090

Affected Products

Idv Directory Viewer