CVE-2006-1777: High severity Simplog Simplog vulnerability
Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter, as demonstrated by injecting PHP sequences into an Apache errorlog file, which is then included by doc/index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1777?
CVE-2006-1777 is classified as a medium severity vulnerability.
How do I fix CVE-2006-1777?
To fix CVE-2006-1777, upgrade to Simplog version 0.9.3 or later where this vulnerability is addressed.
What does CVE-2006-1777 allow attackers to do?
CVE-2006-1777 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the s parameter.
Which versions of Simplog are affected by CVE-2006-1777?
CVE-2006-1777 affects Simplog versions 0.9.2 and earlier.
In which file is the vulnerability CVE-2006-1777 found?
CVE-2006-1777 is found in the doc/index.php file of the Simplog application.