CVE-2006-6242: Path Traversal
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins/ scripts (2) serendipityeventbbcode/serendipityeventbbcode.php, (3) serendipityeventbrowsercompatibility/serendipityeventbrowsercompatibility.php, (4) serendipityeventcontentrewrite/serendipityeventcontentrewrite.php, (5) serendipityeventcreativecommons/serendipityeventcreativecommons.php, (6) serendipityeventemoticate/serendipityeventemoticate.php, (7) serendipityevententryproperties/serendipityevententryproperties.php, (8) serendipityeventkarma/serendipityeventkarma.php, (9) serendipityeventlivesearch/serendipityeventlivesearch.php, (10) serendipityeventmailer/serendipityeventmailer.php, (11) serendipityeventnl2br/serendipityeventnl2br.php, (12) serendipityevents9ymarkup/serendipityevents9ymarkup.php, (13) serendipityeventsearchhighlight/serendipityeventsearchhighlight.php, (14) serendipityeventspamblock/serendipityeventspamblock.php, (15) serendipityeventspartacus/serendipityeventspartacus.php, (16) serendipityeventstatistics/serendipitypluginstatistics.php, (17) serendipityeventtemplatechooser/serendipityeventtemplatechooser.php, (18) serendipityeventtextile/serendipityeventtextile.php, (19) serendipityeventtextwiki/serendipityeventtextwiki.php, (20) serendipityeventtrackexits/serendipityeventtrackexits.php, (21) serendipityeventweblogping/serendipityeventweblogping.php, (22) serendipityeventxhtmlcleanup/serendipityeventxhtmlcleanup.php, (23) serendipityplugincomments/serendipityplugincomments.php, (24) serendipityplugincreativecommons/serendipityplugincreativecommons.php, (25) serendipitypluginentrylinks/serendipitypluginentrylinks.php, (26) serendipityplugineventwrapper/serendipityplugineventwrapper.php, (27) serendipitypluginhistory/serendipitypluginhistory.php, (28) serendipitypluginrecententries/serendipitypluginrecententries.php, (29) serendipitypluginremoterss/serendipitypluginremoterss.php, (30) serendipitypluginshoutbox/serendipitypluginshoutbox.php, and and (31) serendipityplugintemplatedropdown/serendipityplugintemplatedropdown.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6242?
CVE-2006-6242 is considered to have a high severity due to its potential for exposing sensitive local files through directory traversal vulnerabilities.
How do I fix CVE-2006-6242?
To fix CVE-2006-6242, upgrade Serendipity to the latest version where this vulnerability has been addressed.
Who is affected by CVE-2006-6242?
CVE-2006-6242 affects multiple versions of Serendipity including version 1.0.3 and earlier.
What types of attacks can CVE-2006-6242 enable?
CVE-2006-6242 can enable remote attackers to read or include arbitrary local files on the affected server.
Where can I find more information about CVE-2006-6242?
More information about CVE-2006-6242 can be found in security advisories and forums dedicated to Serendipity.