Back
CVE-2006-0434
Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read arbitrary files via ".." (dot dot) sequences and null bytes in the sAction parameter, a different vulnerability than CVE-2006-0244. NOTE: if the functionality of phpXplorer supports the upload of PHP files, then this issue would not cross privilege boundaries and would not be a vulnerability.
Published: Jan 26, 2006
Modified: Jun 16, 2026
CWE-22
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| phpxplorer | phpxplorer | - |
GitHub Security Advisory GHSA-qqvf-34wx-m9pm
Directory traversal vulnerability in action.php in phpXplorer allows remote attackers to read...
References (6)
- http://www.securityfocus.com/archive/1/422434/100/0/threaded
- http://www.securityfocus.com/bid/16292
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39982
- http://www.securityfocus.com/archive/1/422434/100/0/threaded
- http://www.securityfocus.com/bid/16292
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39982
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
1.76%
Top 24% most likely to be exploited
Threat Score
20.5 / 100
Data Sources
NVD
EPSS
GitHub