Vulnerability Name: | CVE-2006-2658 (CCN-28861) | ||||||||
Assigned: | 2006-09-08 | ||||||||
Published: | 2006-09-08 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:TF/RC:C)
4.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:TF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2658 Source: SUSE Type: Vendor Advisory SUSE-SR:2006:022 Source: CCN Type: SA21840 XSP Directory Traversal Vulnerability Source: SECUNIA Type: Vendor Advisory 21840 Source: SECUNIA Type: UNKNOWN 21847 Source: CCN Type: SECTRACK ID: 1016821 Mono Web Server `xsp` Component Lets Remote Users Traverse the Directory Source: SECTRACK Type: UNKNOWN 1016821 Source: CCN Type: XSP Web site ASP.NET - Mono Source: CCN Type: OSVDB ID: 28743 Mono/C# Web Server mod_mono xsp Component Traversal Arbitrary File Access Source: BID Type: UNKNOWN 19929 Source: CCN Type: BID-19929 Mono XSP Unspecified Directory Traversal Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-3552 Source: XF Type: UNKNOWN xsp-url-directory-traversal(28861) Source: SUSE Type: SUSE-SR:2006:022 SUSE Security Summary Report | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |