CVE-2006-6392
Estado: ModificadaAlta (7.5)—
Directory traversal vulnerability in index.php in plx Web Studio (aka plxWebDev) plx Pay 3.2 and earlier allows remote attackers to include and execute arbitrary local files, or obtain user credentials and other sensitive information, via a .. (dot dot) in the read parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.75%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/23190
- http://www.securityfocus.com/bid/21379
- http://www.vupen.com/english/advisories/2006/4809
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30619
- http://secunia.com/advisories/23190
- http://www.securityfocus.com/bid/21379
- http://www.vupen.com/english/advisories/2006/4809
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30619
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-6392",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-12-08T01:28:00.000",
"references": [
{
"url": "http://secunia.com/advisories/23190",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21379",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4809",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30619",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23190",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21379",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4809",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30619",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Directory traversal vulnerability in index.php in plx Web Studio (aka plxWebDev) plx Pay 3.2 and earlier allows remote attackers to include and execute arbitrary local files, or obtain user credentials and other sensitive information, via a .. (dot dot) in the read parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."
},
{
"lang": "es",
"value": "Vulnerabilidad de escalado de directorio en index.php del plx Web Studio (también conocido como plxWebDev), plx Pay 3.2 y versiones anteriores permite a atacantes remotos la inclusión y ejecución de ficheros locales de su elección, o la obtención de las credenciales del usuario, así como de otra información sensible, mediante .. (punto punto)en el parámetro read. NOTA: la procedencia de esta información es desconocida; los detalles se obtienen a partir de la información de terceros."
}
],
"lastModified": "2026-06-16T22:33:01.470",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:plx_web_studio:plx_pay:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "692E02C2-3A87-44F9-A8E6-01C948A0DD10",
"versionEndIncluding": "3.2"
},
{
"criteria": "cpe:2.3:a:plx_web_studio:plx_pay:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85BF9492-19D6-4ACE-8458-A5CBB1EEC0CF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}