CVE-2006-6569 EXPLOIT
7.8
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 86)
Patch early
A public exploit exists.
Description
form.php in GenesisTrader 1.0 allows remote attackers to read source code for arbitrary files and obtain sensitive information via the (1) do and (2) chem parameters with a "modfich" floap parameter.
Scoring
| CVSS | 7.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
| EPSS | 2.75% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-12-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| genesistrader | genesistrader |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GenesisTrader 1.0 - 'form.php' Arbitrary File Source Disclosure | 2006-12-14 |
References
- http://securityreason.com/securityalert/2035
- http://www.securityfocus.com/archive/1/454385/100/0/threaded
- http://www.securityfocus.com/bid/21595
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30888
- http://securityreason.com/securityalert/2035
- http://www.securityfocus.com/archive/1/454385/100/0/threaded
- http://www.securityfocus.com/bid/21595
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30888
→ the Explorer · watch your stack · NVD