Back

CVE-2006-0132

Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows remote attackers to include and execute arbitrary local PHP scripts, and possibly read other types of files, via a .. (dot dot) and a trailing null in the webftp_language parameter.

Published: Jan 9, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
webftp webftp 1.2.6

GitHub Security Advisory GHSA-3qq5-8frq-x9jh

Directory traversal vulnerability in webftp.php in SysCP WebFTP 1.2.6 and possibly earlier allows...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.60%

Top 27% most likely to be exploited

Threat Score 20.5 / 100

Data Sources

NVD EPSS GitHub