peter bassill · operator
$ cve CVE-2006-7133 JSON

CVE-2006-7133 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 2.9% (pctl 86)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.9% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2007-03-06
Last modified2026-06-16

Affected (1)

VendorProduct
php upload toolphp upload tool

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD