CVE-2006-2295 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3% (pctl 87)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.97% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-05-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| timobraun | dynamic galerie |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | timobraun Dynamic Galerie 1.0 - 'index.php?pfad' Arbitrary Directory Listing | 2006-05-08 |
| exploit-db | timobraun Dynamic Galerie 1.0 - 'galerie.php?pfad' Arbitrary Directory Listing | 2006-05-08 |
References
- http://d4igoro.blogspot.com/2006/05/dynamic-galerie-10-path-traversal-xss.html
- http://secunia.com/advisories/19995
- http://www.securityfocus.com/bid/17896
- http://www.vupen.com/english/advisories/2006/1699
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26322
- http://d4igoro.blogspot.com/2006/05/dynamic-galerie-10-path-traversal-xss.html
- http://secunia.com/advisories/19995
- http://www.securityfocus.com/bid/17896
- http://www.vupen.com/english/advisories/2006/1699
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26322
→ the Explorer · watch your stack · NVD