CVE-2006-7112: Path Traversal
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read and include arbitrary files via the PNSVlang cookie, as demonstrated by uploading a GIF image using AddDownload or injecting PHP code into a log file, then accessing it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7112?
CVE-2006-7112 is considered a medium severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2006-7112?
To mitigate CVE-2006-7112, upgrade to a later version of MD-Pro that has resolved this directory traversal vulnerability.
Who is affected by CVE-2006-7112?
CVE-2006-7112 affects users of MD-Pro versions 1.0.76 and earlier, particularly those with authenticated access.
What types of files can be accessed through CVE-2006-7112?
CVE-2006-7112 can potentially allow access to any arbitrary files on the server due to directory traversal.
Can CVE-2006-7112 be exploited remotely?
Yes, CVE-2006-7112 can be exploited remotely by authenticated users to read and include arbitrary files.