CVE-2006-0910
published 2006-02-28CVE-2006-0910: Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1)…
PriorityP423medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.34%
67.7th percentile
Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6) ips_kernel/PEAR/Text/Diff/, (7) ips_kernel/PEAR/Text/Diff/Renderer/, (8) style_images/1/folder_rte_files/, (9) style_images/1/folder_js_skin/, (10) style_images/1/folder_rte_images/, and (11) upgrade/ and its subdirectories.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
| invision_power_services | invision_power_board | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
bugzilla·2007-02-20·CVSS 7.5
CVE-2007-0906 [HIGH] CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
+++ This bug was initially created as a clone of Bug #228858 +++
Description of problem:
1. If unserializing untrusted data on 64-bit platforms the
zend_hash_init() function can be forced to enter an infinite loop,
consuming CPU resources, for a limited length of time, until the
script timeout alarm aborts the script (CVE-2007-0988)
2. If a script uses the imap_mail_compose() function to create a new MIME
message based on an input body from an untrusted source, an attacker may be able
to force a heap overflow (CVE-2006-0906)
3. If the format string could passed to one of the functions in the printf()
family could be controlled by an attacker via untrusted data, then an
out-of-b
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
bugzilla·2007-02-16·CVSS 7.5
CVE-2007-0906 [HIGH] CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
+++ This bug was initially created as a clone of Bug #228858 +++
Description of problem:
1. If unserializing untrusted data on 64-bit platforms the
zend_hash_init() function can be forced to enter an infinite loop,
consuming CPU resources, for a limited length of time, until the
script timeout alarm aborts the script (CVE-NO-NAME)
2. If a script uses the imap_mail_compose() function to create a new MIME
message based on an input body from an untrusted source, an attacker may be able
to force a heap overflow (CVE-2006-0906)
3. If the format string could passed to one of the functions in the printf()
family could be controlled by an attacker via untrusted data, then an
out-of-bou
Bugzilla
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
bugzilla·2007-02-15·CVSS 7.5
CVE-2007-0906 [HIGH] CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
CVE-2007-0906 PHP security issues (CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988)
Description of problem:
1. If unserializing untrusted data on 64-bit platforms the
zend_hash_init() function can be forced to enter an infinite loop,
consuming CPU resources, for a limited length of time, until the
script timeout alarm aborts the script (CVE-NO-NAME)
2. If a script uses the imap_mail_compose() function to create a new MIME
message based on an input body from an untrusted source, an attacker may be able
to force a heap overflow (CVE-2006-0906)
3. If the format string could passed to one of the functions in the printf()
family could be controlled by an attacker via untrusted data, then an
out-of-bounds memory read could crash the Apache child process (CVE-2006-090
http://neosecurityteam.net/advisories/Advisory-16.txthttp://neosecurityteam.net/index.php?action=advisories&id=16http://www.securityfocus.com/archive/1/425713/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/24840http://neosecurityteam.net/advisories/Advisory-16.txthttp://neosecurityteam.net/index.php?action=advisories&id=16http://www.securityfocus.com/archive/1/425713/100/0/threadedhttps://exchange.xforce.ibmcloud.com/vulnerabilities/24840
2006-02-28
Published