PT-2006-1174 · Idv · Idv Directory Viewer
Published
2006-01-05
·
Updated
2011-03-08
·
CVE-2006-0090
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
IDV Directory Viewer versions prior to 2005.1
Description:
The issue allows remote attackers to view arbitrary directory contents. This is achieved by using a .. (dot dot) in the
dir parameter of the index.php file, enabling directory traversal.Recommendations:
For versions prior to 2005.1, update to version 2005.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the index.php file or disabling the
dir parameter to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Idv Directory Viewer