Back

CVE-2006-0347

Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

Published: Jan 21, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (20)

Vendor Product Version
stefan_ritt elog_web_logbook 2.0.0
stefan_ritt elog_web_logbook 2.0.1
stefan_ritt elog_web_logbook 2.0.2
stefan_ritt elog_web_logbook 2.0.3
stefan_ritt elog_web_logbook 2.0.4
stefan_ritt elog_web_logbook 2.0.5
stefan_ritt elog_web_logbook 2.1.0
stefan_ritt elog_web_logbook 2.1.1
stefan_ritt elog_web_logbook 2.1.2
stefan_ritt elog_web_logbook 2.1.3
stefan_ritt elog_web_logbook 2.2.0
stefan_ritt elog_web_logbook 2.2.1
stefan_ritt elog_web_logbook 2.2.2
stefan_ritt elog_web_logbook 2.2.3
stefan_ritt elog_web_logbook 2.2.4
stefan_ritt elog_web_logbook 2.4
stefan_ritt elog_web_logbook 2.5
stefan_ritt elog_web_logbook 2.5.6
stefan_ritt elog_web_logbook 2.5.7
stefan_ritt elog_web_logbook 2.6.0

GitHub Security Advisory GHSA-xghq-r485-w5jv

Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.00%

Top 21% most likely to be exploited

Threat Score 20.6 / 100

Data Sources

NVD EPSS GitHub