PT-2006-6913 · Vikingboard · Vikingboard

Benjamin Moss

+1

·

Published

2006-12-04

·

Updated

2018-10-17

·

CVE-2006-6284

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Vikingboard version 0.1.2
Description The issue allows remote authenticated administrators to include arbitrary files via a .. (dot dot) sequence in the act parameter of the admin.php file.
Recommendations For Vikingboard version 0.1.2, consider restricting access to the admin.php file to prevent exploitation, and avoid using the act parameter with unvalidated input until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6284

Affected Products

Vikingboard