CVE-2006-1095
published 2006-03-09CVE-2006-1095: Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted…
PriorityP422high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.87%
54.7th percentile
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mod_python | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2006-1095: Directory traversal vulnerability in the FileSession object in Mod_python module 3
vendor_redhat·CVSS 7.2
CVE-2006-1095 [HIGH] CVE-2006-1095: Directory traversal vulnerability in the FileSession object in Mod_python module 3
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
Statement: This issue did not affect the versions of mod_python as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.
GHSA
GHSA-wh8r-wrrv-8p2r: Directory traversal vulnerability in the FileSession object in Mod_python module 3
ghsa_unreviewed·2022-05-01
CVE-2006-1095 [HIGH] CWE-22 GHSA-wh8r-wrrv-8p2r: Directory traversal vulnerability in the FileSession object in Mod_python module 3
Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/19239http://securitytracker.com/id?1015764http://svn.apache.org/viewcvs.cgi/httpd/mod_python/branches/3.2.x/NEWS?rev=378945http://www.cgisecurity.com/2006/02/07http://www.modpython.org/fs_sec_warn.htmlhttp://www.securityfocus.com/bid/16916http://www.vupen.com/english/advisories/2006/0768https://exchange.xforce.ibmcloud.com/vulnerabilities/24965http://secunia.com/advisories/19239http://securitytracker.com/id?1015764http://svn.apache.org/viewcvs.cgi/httpd/mod_python/branches/3.2.x/NEWS?rev=378945http://www.cgisecurity.com/2006/02/07http://www.modpython.org/fs_sec_warn.htmlhttp://www.securityfocus.com/bid/16916http://www.vupen.com/english/advisories/2006/0768https://exchange.xforce.ibmcloud.com/vulnerabilities/24965
2006-03-09
Published