← Back

CVE-2006-6376

nvd nist
Published: Dec 7, 2006Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.

Affected (1)

1 product
Simple File Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.24a

References (4)

Timeline

No history available yet.