CVE-2006-5031: Path Traversal
Published Sep 27, 2006
·Updated
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.
Affected Software
2 affected components
Cakefoundation Cakephp<=1.1.7.3363
CakePHP CakePHP<=1.1.7.3363
Remediation
Patch Available
Event History
Sep 27, 2006
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
via NVD·11:07 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5031?
CVE-2006-5031 has a medium severity rating due to its potential to allow remote file access.
2
How do I fix CVE-2006-5031?
To fix CVE-2006-5031, upgrade to CakePHP version 1.1.8.3544 or later.
3
What effects does CVE-2006-5031 have on affected systems?
CVE-2006-5031 can allow attackers to read arbitrary files from the server, leading to information disclosure.
4
Which versions of CakePHP are affected by CVE-2006-5031?
CVE-2006-5031 affects CakePHP versions prior to 1.1.8.3544, specifically up to version 1.1.7.3363.
5
What type of vulnerability is CVE-2006-5031?
CVE-2006-5031 is a directory traversal vulnerability.