{"api_version":"1","generated_at":"2026-07-23T09:00:28+00:00","cve":"CVE-2006-3426","urls":{"html":"https://cve.report/CVE-2006-3426","api":"https://cve.report/api/cve/CVE-2006-3426.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3426","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3426"},"summary":{"title":"CVE-2006-3426","description":"Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-07 00:05:00","updated_at":"2018-10-18 16:47:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://securitytracker.com/id?1016405","name":"1016405","refsource":"SECTRACK","tags":[],"title":"PatchLink Update Bugs Let Remote Users Inject SQL Commands, Modify the Configuration, and Create or Overwrite Files - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2596","name":"ADV-2006-2596","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1200","name":"1200","refsource":"SREASON","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/18732","name":"18732","refsource":"BID","tags":[],"title":"PatchLink Update Server Arbitrary File Overwrite Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/20876","name":"20876","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2595","name":"ADV-2006-2595","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html","name":"20060629 Multiple Vulnerabilities in PatchLink Update Server 6","refsource":"FULLDISC","tags":[],"title":"[Full-disclosure] Multiple Vulnerabilities in PatchLink Update\n\tServer 6","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/438710/100/0/threaded","name":"20060629 Multiple Vulnerabilities in PatchLink Update Server 6","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20878","name":"20878","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Novell ZENworks Patch Management Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3426","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3426","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.2.0.181","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.2.0.189","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.2.0.181","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"lumension","cpe5":"patchlink_update_server","cpe6":"6.2.0.189","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3426","vulnerable":"1","versionEndIncluding":"6.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"novell","cpe5":"zenworks","cpe6":"*","cpe7":"sr1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3426","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060629 Multiple Vulnerabilities in PatchLink Update Server 6","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html"},{"name":"18732","refsource":"BID","url":"http://www.securityfocus.com/bid/18732"},{"name":"20060629 Multiple Vulnerabilities in PatchLink Update Server 6","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/438710/100/0/threaded"},{"name":"20876","refsource":"SECUNIA","url":"http://secunia.com/advisories/20876"},{"name":"20878","refsource":"SECUNIA","url":"http://secunia.com/advisories/20878"},{"name":"1200","refsource":"SREASON","url":"http://securityreason.com/securityalert/1200"},{"name":"ADV-2006-2596","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2596"},{"name":"ADV-2006-2595","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2595"},{"name":"1016405","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016405"}]}},"nvd":{"publishedDate":"2006-07-07 00:05:00","lastModifiedDate":"2018-10-18 16:47:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:novell:zenworks:*:sr1:*:*:*:*:*:*","versionEndIncluding":"6.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lumension:patchlink_update_server:6.2.0.181:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:lumension:patchlink_update_server:6.2.0.189:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3426","Ordinal":"18751","Title":"CVE-2006-3426","CVE":"CVE-2006-3426","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3426","Ordinal":"1","NoteData":"Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3426","Ordinal":"2","NoteData":"2006-07-06","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3426","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}