First published: Thu Dec 14 2006(Updated: )
Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Flippet.org Winamp Web Interface | <=7.5.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6512 is considered a moderate severity vulnerability due to the potential for unauthorized access to system directories.
To fix CVE-2006-6512, upgrade to a version of Winamp Web Interface later than 7.5.13 which is not affected by this vulnerability.
CVE-2006-6512 affects remote authenticated users of Winamp Web Interface versions 7.5.13 and earlier.
CVE-2006-6512 enables directory traversal attacks, allowing attackers to list arbitrary directories.
Exploitation of CVE-2006-6512 requires authentication, as the vulnerability affects only authenticated users.