{"api_version":"1","generated_at":"2026-07-23T14:42:58+00:00","cve":"CVE-2006-2839","urls":{"html":"https://cve.report/CVE-2006-2839","api":"https://cve.report/api/cve/CVE-2006-2839.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2839","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2839"},"summary":{"title":"CVE-2006-2839","description":"Directory traversal vulnerability in PG Problem Editor module (PGProblemEditor.pm) in WeBWorK Online Homework Delivery System 2.2.0 and earlier allows remote attackers to read and write files outside of the templates directory.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-06 20:06:00","updated_at":"2017-07-20 01:31:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt2pt1","name":"http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt2pt1","refsource":"CONFIRM","tags":[],"title":"WeBWorK-TWiki . Webwork . WeBWorKRelease2pt2pt1","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26975","name":"webwork-pgproblemeditor-security-bypass(26975)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sourceforge.net/mailarchive/forum.php?thread_id=10201693&forum_id=43257","name":"http://sourceforge.net/mailarchive/forum.php?thread_id=10201693&forum_id=43257","refsource":"CONFIRM","tags":[],"title":"Page not found\n    - SourceForge.net","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://sourceforge.net/project/shownotes.php?release_id=421453","name":"http://sourceforge.net/project/shownotes.php?release_id=421453","refsource":"CONFIRM","tags":[],"title":"Page not found\n    - SourceForge.net","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://secunia.com/advisories/20405","name":"20405","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"WeBWorK \"PG Problem Editor\" File Access Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2086","name":"ADV-2006-2086","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2839","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2839","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2839","vulnerable":"1","versionEndIncluding":"2.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webwork","cpe5":"webwork","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2839","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in PG Problem Editor module (PGProblemEditor.pm) in WeBWorK Online Homework Delivery System 2.2.0 and earlier allows remote attackers to read and write files outside of the templates directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-2086","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2086"},{"name":"20405","refsource":"SECUNIA","url":"http://secunia.com/advisories/20405"},{"name":"webwork-pgproblemeditor-security-bypass(26975)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26975"},{"name":"http://sourceforge.net/project/shownotes.php?release_id=421453","refsource":"CONFIRM","url":"http://sourceforge.net/project/shownotes.php?release_id=421453"},{"name":"http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt2pt1","refsource":"CONFIRM","url":"http://devel.webwork.rochester.edu/twiki/bin/view/Webwork/WeBWorKRelease2pt2pt1"},{"name":"http://sourceforge.net/mailarchive/forum.php?thread_id=10201693&forum_id=43257","refsource":"CONFIRM","url":"http://sourceforge.net/mailarchive/forum.php?thread_id=10201693&forum_id=43257"}]}},"nvd":{"publishedDate":"2006-06-06 20:06:00","lastModifiedDate":"2017-07-20 01:31:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:webwork:webwork:*:*:*:*:*:*:*:*","versionEndIncluding":"2.2.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2839","Ordinal":"18159","Title":"CVE-2006-2839","CVE":"CVE-2006-2839","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2839","Ordinal":"1","NoteData":"Directory traversal vulnerability in PG Problem Editor module (PGProblemEditor.pm) in WeBWorK Online Homework Delivery System 2.2.0 and earlier allows remote attackers to read and write files outside of the templates directory.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2839","Ordinal":"2","NoteData":"2006-06-06","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2839","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}