Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1...
Vulnerability Description
Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to unb_lib/abbc.css.php.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-2405
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/20090
- http://retrogod.altervista.org/unb_161p1_incl_xpl.html
- http://securityreason.com/securityalert/899
- http://www.securityfocus.com/archive/1/433686/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26507
- http://www.osvdb.org/25494
- http://newsboard.unclassified.de/forum/post/6499
- http://www.securityfocus.com/bid/17947
- http://www.vupen.com/english/advisories/2006/1782
More from unclassified newsboard
View All →Affected Vendor
unclassified newsboard
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.