CVE-2006-2658

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/09/2006
Last modified:
03/04/2025

Description

Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mono:xsp:*:*:*:*:*:*:*:*
cpe:2.3:a:suse:suse_open_enterprise_server:1:*:*:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.2:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:9.3:*:x86_64:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.0:*:oss:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.0:*:professional:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.1:*:personal:*:*:*:*:*
cpe:2.3:o:suse:suse_linux:10.1:*:professional:*:*:*:*:*