CVE-2006-6376
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/12/2006
Last modified:
09/04/2025
Description
Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:onedotoh:simple_file_manager:0.24a:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page