peter bassill · operator
$ cve CVE-2006-3836 JSON

CVE-2006-3836 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS3.5% — more likely to be exploited than 89% of all CVEs
On CISA KEVno
Public exploityes
Published2006-07-25
Last modified2026-06-16

Affected (1)

VendorProduct
unidomediachameleon le

Public exploits

SourceTitleDate
exploit-dbChameleon LE 1.203 - 'index.php' Directory Traversal2006-07-21

References

→ the Explorer  ·  watch your stack  ·  NVD