Back

CVE-2006-0702

admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (dot dot) sequences in the path parameter. NOTE: due to the lack of details, the specific vulnerability type cannot be determined, although it might be due to directory traversal.

Published: Feb 15, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
imagevue imagevue 0.16.1

GitHub Security Advisory GHSA-hx74-56pv-vfr2

admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 7.27%

Top 6% most likely to be exploited

Threat Score 22.2 / 100

Data Sources

NVD EPSS GitHub