CVE-2006-2658

6 documents6 sources
Severity
5.0MEDIUM
EPSS
0.7%
top 28.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12
Latest updateMay 1

Description

Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDsuse/suse_linux4 versions+3
Debianxsp< 1.1.15-1+1

🔴Vulnerability Details

3
GHSA
GHSA-929v-wf58-724f: Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 92022-05-01
OSV
CVE-2006-2658: Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 92006-09-12
CVEList
CVE-2006-2658: Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 92006-09-12

📋Vendor Advisories

1
Debian
CVE-2006-2658: xsp - Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# we...2006

💬Community

1
Bugzilla
CVE-2006-2658: xsp directory traversal vulnerability2006-09-14