CVE-2006-2406 describes a directory traversal vulnerability in Unclassified NewsBoard (UNB) versions 1.5.3-d and potentially earlier, specifically within the bb_lib/abbc.css.php component when register_globals is enabled. An attacker can exploit this by manipulating the design_path parameter with dot-dot sequences and a null byte to include arbitrary local files. The CVSS score of 2.6 (low severity) indicates a network-based attack with high access complexity, requiring no authentication, and primarily impacting integrity (partial). While no Metasploit or Nuclei modules exist, an ExploitDB entry for a related UNB version suggests proof-of-concept code may be available, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5.3dCPE matchmatch criteria | cpe:2.3:a:unclassified_newsboard:unclassified_newsboard:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.