peter bassill · operator
$ cve CVE-2006-2295 JSON

CVE-2006-2295 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.97% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-10
Last modified2026-06-16

Affected (1)

VendorProduct
timobraundynamic galerie

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD