CVE-2006-1800
Summary
| CVE | CVE-2006-1800 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-04-18 10:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS: 0.026230000 probability, percentile 0.838640000 (date 2026-07-22)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Simplemedia | Simplebbs | 1.0.6 | All | All | All |
| Application | Simplemedia | Simplebbs | 1.0.7 | All | All | All |
| Application | Simplemedia | Simplebbs | 1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Vendor Advisory |
| www.worlddefacers.de/Public/WD-SMPL.txt | af854a3a-2127-422b-91ae-364da2661108 | www.worlddefacers.de | Exploit |
| SimpleBBS Remote Arbitrary Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| downloads.securityfocus.com/vulnerabilities/exploits/SimpleBBS-RCE-posts.php.pl | af854a3a-2127-422b-91ae-364da2661108 | downloads.securityfocus.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.