peter bassill · operator
$ cve CVE-2006-0660 JSON

CVE-2006-0660 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 4.7% (pctl 92)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS4.73% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-13
Last modified2026-06-16

Affected (1)

VendorProduct
farsinewsfarsinews

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD