CVE-2006-3836 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 3.5% — more likely to be exploited than 89% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-07-25 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| unidomedia | chameleon le |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Chameleon LE 1.203 - 'index.php' Directory Traversal | 2006-07-21 |
References
- http://secunia.com/advisories/21156
- http://securityreason.com/securityalert/1280
- http://www.securityfocus.com/archive/1/440765/100/0/threaded
- http://www.securityfocus.com/bid/19107
- http://www.vupen.com/english/advisories/2006/2948
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27898
- http://secunia.com/advisories/21156
- http://securityreason.com/securityalert/1280
- http://www.securityfocus.com/archive/1/440765/100/0/threaded
- http://www.securityfocus.com/bid/19107
- http://www.vupen.com/english/advisories/2006/2948
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27898
→ the Explorer · watch your stack · NVD