Back

CVE-2006-0899

Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.

Published: Feb 27, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
4images image_gallery_management_system *

GitHub Security Advisory GHSA-796x-phgf-g22f

Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 9.98%

Top 5% most likely to be exploited

Threat Score 33 / 100

Data Sources

NVD EPSS GitHub