Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2100

Overview

Vulnerability Score 7.8 7.8
CVE Id CVE-2006-2100
Last Modified 07 Mar 2011 09:35:15
Published 29 Apr 2006 06:02:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2100

Summary

Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

Vulnerable Systems

Application

  • Magic Iso Maker 5.0 Build 0166

  • Magic Iso Maker 5.2 Build 190


References

VUPEN - ADV-2006-1568

BUGTRAQ - 20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability

MISC - http://secway.org/advisory/AD20060428.txt

SECUNIA - 19864

XF - iso-dotdot-directory-traversal(26140)

BID - 17725

SECTRACK - 1016007

SREASON - 815


Last Updated: 27 May 2016 10:42:20