CVE-2006-4490 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 3.5% (pctl 89)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
| EPSS | 3.47% — more likely to be exploited than 89% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-08-31 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| cybozu | cybozu office |
| cybozu | share 360 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Cybozu Products - 'id' Arbitrary File Retrieval | 2006-08-28 |
References
- http://cybozu.co.jp/products/dl/notice_060825/
- http://jvn.jp/jp/JVN%2390420168/index.html
- http://secunia.com/advisories/21618
- http://secunia.com/advisories/21623
- http://securitytracker.com/id?1016759
- http://vuln.sg/cybozu-en.html
- http://www.osvdb.org/28261
- http://www.osvdb.org/28262
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28591
- http://cybozu.co.jp/products/dl/notice_060825/
- http://jvn.jp/jp/JVN%2390420168/index.html
- http://secunia.com/advisories/21618
- http://secunia.com/advisories/21623
- http://securitytracker.com/id?1016759
- http://vuln.sg/cybozu-en.html
- http://www.osvdb.org/28261
- http://www.osvdb.org/28262
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28591
→ the Explorer · watch your stack · NVD