CVE-2006-5971: Path Traversal
Published Nov 18, 2006
·Updated
Absolute path traversal vulnerability in admin/logfile.txt in Verity Ultraseek before 5.6.2 allows remote attackers to read arbitrary files via the name variable.
Affected Software
1 affected component
Verity Ultraseek<=5.6.2
Event History
Nov 18, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:07 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5971?
CVE-2006-5971 is classified as a high severity vulnerability due to its potential to allow remote attackers to read arbitrary files.
2
How do I fix CVE-2006-5971?
To remediate CVE-2006-5971, upgrade Verity Ultraseek to version 5.6.2 or later, which patches the vulnerability.
3
What versions of Verity Ultraseek are affected by CVE-2006-5971?
CVE-2006-5971 affects all versions of Verity Ultraseek prior to 5.6.2.
4
What type of attack does CVE-2006-5971 enable?
CVE-2006-5971 enables a path traversal attack that allows attackers to access sensitive files on the server.
5
Who can exploit CVE-2006-5971?
CVE-2006-5971 can be exploited by remote attackers with no authentication required to access sensitive information.