CVE-2006-1073: Medium severity Simplog Simplog vulnerability
Published Mar 8, 2006
·Updated
Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.
Affected Software
1 affected component
Simplog Simplog<=1.0.2
Event History
Mar 8, 2006
CVE Published
via NVD·12:02 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1073?
CVE-2006-1073 is considered a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2006-1073?
To fix CVE-2006-1073, you should upgrade Daverave Simplog to version 1.0.3 or later.
3
What types of attacks can exploit CVE-2006-1073?
CVE-2006-1073 can be exploited through directory traversal attacks to read arbitrary .txt files.
4
Which versions of Simplog are affected by CVE-2006-1073?
CVE-2006-1073 affects Daverave Simplog version 1.0.2 and earlier.
5
What parameters are involved in the exploitation of CVE-2006-1073?
The exploit for CVE-2006-1073 involves the 'act' and 'blogid' parameters in index.php.