CVE-2006-0660 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 4.7% (pctl 92)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
| EPSS | 4.73% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| farsinews | farsinews |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Farsinews 2.5 - Directory Traversal Arbitrary 'users.db' Access | 2006-02-28 |
| exploit-db | Farsinews 2.1/2.5 - 'show_archives.php?template' Traversal Arbitrary File Access | 2006-02-10 |
References
- http://forum.farsinewsteam.com/index.php?showtopic=71
- http://forum.farsinewsteam.com/index.php?showtopic=76
- http://secunia.com/advisories/18768
- http://www.hamid.ir/security/farsinews2-5.txt
- http://www.osvdb.org/23020
- http://www.osvdb.org/23021
- http://www.osvdb.org/23022
- http://www.securityfocus.com/archive/1/424720/100/0/threaded
- http://www.securityfocus.com/bid/16580
- http://www.vupen.com/english/advisories/2006/0506
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24598
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24602
- http://forum.farsinewsteam.com/index.php?showtopic=71
- http://forum.farsinewsteam.com/index.php?showtopic=76
- http://secunia.com/advisories/18768
- http://www.hamid.ir/security/farsinews2-5.txt
- http://www.osvdb.org/23020
- http://www.osvdb.org/23021
- http://www.osvdb.org/23022
- http://www.securityfocus.com/archive/1/424720/100/0/threaded
→ the Explorer · watch your stack · NVD