{"api_version":"1","generated_at":"2026-07-23T11:48:10+00:00","cve":"CVE-2006-1383","urls":{"html":"https://cve.report/CVE-2006-1383","api":"https://cve.report/api/cve/CVE-2006-1383.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1383","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1383"},"summary":{"title":"CVE-2006-1383","description":"Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-24 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/17205","name":"http://www.securityfocus.com/bid/17205","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Baby FTP Server Information Disclosure Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/24057","name":"http://www.osvdb.org/24057","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/19338","name":"http://secunia.com/advisories/19338","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Baby FTP Server File Enumeration Weakness - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25413","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25413","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1069","name":"http://www.vupen.com/english/advisories/2006/1069","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1383","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1383","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1383","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pablo_software_solutions","cpe5":"baby_ftp_server","cpe6":"1.24","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1383","cve":"CVE-2006-1383","epss":"0.007180000","percentile":"0.724790000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:21.286Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17205","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17205"},{"name":"baby-ftp-information-disclosure(25413)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25413"},{"name":"19338","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19338"},{"name":"ADV-2006-1069","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1069"},{"name":"24057","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24057"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17205","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17205"},{"name":"baby-ftp-information-disclosure(25413)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25413"},{"name":"19338","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19338"},{"name":"ADV-2006-1069","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1069"},{"name":"24057","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24057"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1383","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17205","refsource":"BID","url":"http://www.securityfocus.com/bid/17205"},{"name":"baby-ftp-information-disclosure(25413)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25413"},{"name":"19338","refsource":"SECUNIA","url":"http://secunia.com/advisories/19338"},{"name":"ADV-2006-1069","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1069"},{"name":"24057","refsource":"OSVDB","url":"http://www.osvdb.org/24057"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1383","datePublished":"2006-03-24T11:00:00.000Z","dateReserved":"2006-03-24T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:21.286Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-24 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pablo_software_solutions:baby_ftp_server:1.24:*:*:*:*:*:*:*","matchCriteriaId":"1CF066D6-27C4-4F35-86C9-9FA713A2F790"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1383","Ordinal":"1","Title":"CVE-2006-1383","CVE":"CVE-2006-1383","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1383","Ordinal":"1","NoteData":"Directory traversal vulnerability in Baby FTP Server (BabyFTP) 1.24 allows remote authenticated users to determine existence of files outside the intended document root via unspecified manipulations, which generate different error messages depending on whether a file exists or not.","Type":"Description","Title":"CVE-2006-1383"},{"CveYear":"2006","CveId":"1383","Ordinal":"2","NoteData":"2006-03-24","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1383","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}