{"api_version":"1","generated_at":"2026-07-23T06:22:57+00:00","cve":"CVE-2006-0132","urls":{"html":"https://cve.report/CVE-2006-0132","api":"https://cve.report/api/cve/CVE-2006-0132.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0132","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0132"},"summary":{"title":"CVE-2006-0132","description":"Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-09 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/420973/100/0/threaded","name":"http://www.securityfocus.com/archive/1/420973/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24018","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24018","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16175","name":"http://www.securityfocus.com/bid/16175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SysCP WebFTP Module Local File Include Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0090","name":"http://www.vupen.com/english/advisories/2006/0090","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18355","name":"http://secunia.com/advisories/18355","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - SysCP WebFTP Module \"webftp_language\" Local File Inclusion Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0132","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0132","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"132","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webftp","cpe5":"webftp","cpe6":"1.2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:34.103Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"webftp-language-file-include(24018)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24018"},{"name":"20060104 SysCP WebFTP local file inclusion vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/420973/100/0/threaded"},{"name":"18355","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18355"},{"name":"16175","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16175"},{"name":"ADV-2006-0090","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0090"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"webftp-language-file-include(24018)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24018"},{"name":"20060104 SysCP WebFTP local file inclusion vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/420973/100/0/threaded"},{"name":"18355","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18355"},{"name":"16175","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16175"},{"name":"ADV-2006-0090","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0090"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0132","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"webftp-language-file-include(24018)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24018"},{"name":"20060104 SysCP WebFTP local file inclusion vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/420973/100/0/threaded"},{"name":"18355","refsource":"SECUNIA","url":"http://secunia.com/advisories/18355"},{"name":"16175","refsource":"BID","url":"http://www.securityfocus.com/bid/16175"},{"name":"ADV-2006-0090","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0090"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0132","datePublished":"2006-01-09T11:00:00.000Z","dateReserved":"2006-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:34.103Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-09 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webftp:webftp:1.2.6:*:*:*:*:*:*:*","matchCriteriaId":"304215A3-885C-4486-A022-6FF0F3F94579"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"132","Ordinal":"1","Title":"CVE-2006-0132","CVE":"CVE-2006-0132","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"132","Ordinal":"1","NoteData":"Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.","Type":"Description","Title":"CVE-2006-0132"},{"CveYear":"2006","CveId":"132","Ordinal":"2","NoteData":"2006-01-09","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"132","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}