Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2101

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2101
Last Modified 07 Mar 2011 09:35:15
Published 29 Apr 2006 06:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2101

Summary

Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

Vulnerable Systems

Application

  • Winiso Computing Winiso 5.3


References

VUPEN - ADV-2006-1567

BUGTRAQ - 20060428 WinISO/UltraISO/MagicISO/PowerISO Directory Traversal Vulnerability

MISC - http://secway.org/advisory/AD20060428.txt

SECUNIA - 19816

XF - iso-dotdot-directory-traversal(26140)

BID - 17721

SECTRACK - 1016010

SREASON - 815


Last Updated: 27 May 2016 10:42:20