CVE-2006-4140 - CVE House
Back to Database
Status published Medium CVE-2006-4140

Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows...

Vulnerability Description

Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-4140

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

server monitor
Vulnerable Versions:
4.3.1.368, 4.3.1.382, 4.4.1.521, 4.4.1.522, 5.0.1.272, 5.0.1.299, 5.0.1.309, 5.0.1.321, 5.1.0.341, 5.1.0.342, 5.1.0.345, 5.2.0.404, 5.2.0.405, 5.2.0.418, 5.2.0.420, 5.2.2.449, 5.2.2.451, 5.3.0.506, 5.3.0.507, 5.3.0.508, 5.3.0.509, 5.3.1.574, 5.3.1.575, 5.3.1.578, 5.3.1.579, 5.3.1.580, 5.3.1.581, 5.3.1.586, 5.3.1.587, 5.3.2.605, 5.3.2.606, 5.3.2.609, 5.3.2.610, 5.3.2.616, 5.3.2.617

Timeline

Official Publish: August 14th, 2006
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.