CVE-2006-6254
Estado: ModificadaMedia (4.3)—
administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.91%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://acid-root.new.fr/poc/15061124.txt
- http://secunia.com/advisories/23122
- http://securityreason.com/securityalert/1961
- http://www.securityfocus.com/archive/1/452600/100/0/threaded
- http://www.securityfocus.com/bid/21283
- http://www.vupen.com/english/advisories/2006/4701
- http://acid-root.new.fr/poc/15061124.txt
- http://secunia.com/advisories/23122
- http://securityreason.com/securityalert/1961
- http://www.securityfocus.com/archive/1/452600/100/0/threaded
- http://www.securityfocus.com/bid/21283
- http://www.vupen.com/english/advisories/2006/4701
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-6254",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-12-04T11:28:00.000",
"references": [
{
"url": "http://acid-root.new.fr/poc/15061124.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23122",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1961",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/452600/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21283",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4701",
"source": "cve@mitre.org"
},
{
"url": "http://acid-root.new.fr/poc/15061124.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23122",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1961",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/452600/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21283",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4701",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope of this issue extends above the web document root, and whether directory traversal is the primary vulnerability."
},
{
"lang": "es",
"value": "administration/telecharger.php en Cahier de texte 2.0 permite a atacantes remotos obtener contenido sin interpretar (código fuente) o archivos mediante el parámetro chemin, como se ha demostrado usando secuencias de salto de directorio para obtener el nombre de usuario y contraseña MySQL de conn_cahier_de_texte.php. NOTA: no está claro si el alcance de este problema se extiende más allá del raíz de documentos web, y si el salto de directorio es la vulnerabilidad principal."
}
],
"lastModified": "2026-06-16T22:32:46.140",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cahier_de_textes:cahier_de_textes:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF1E4F0C-F929-4561-B156-E7FBEB86CE1A",
"versionEndIncluding": "2.2"
},
{
"criteria": "cpe:2.3:a:cahier_de_textes:cahier_de_textes:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F28BDD8-EC76-4A9F-977F-5ED29E7C160E"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "Successful exploitation requirs that \"register_globals\" is enabled."
}