CVE-2006-0315 describes a directory traversal vulnerability in index.php of EZDatabase versions prior to 2.1.2. This flaw allows remote attackers to manipulate the 'p' parameter, leading to the inclusion of arbitrary .php files, resulting in cross-site scripting (XSS) and path disclosure. With a CVSS score of 5.8, this vulnerability has a medium severity, requiring moderate attack complexity and potentially impacting confidentiality and integrity. The attack vector is network-based, meaning no local access is required. While not actively exploited or on the KEV catalog, an ExploitDB entry (EDB-27093) exists for a related XSS vulnerability. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.1CPE matchmatch criteria | cpe:2.3:a:indexcor:ezdatabase:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.