CVE-2006-0785
Absolute path traversal vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to include and execute arbitrary local files via a direct request with a path parameter with a null character and beginning with (1) '/' (slash) for an absolute pathname or (2) a drive letter (such as "C:"), which bypasses checks for ".." sequences and trailing ".php" extensions.
- Affected products
- Phpkit
- Phpkit
- ≤ 1.6.1
- Fix
- Available
- CVSS 2.0
- 6.4 MEDIUM
- EPSS
- 1.6% (73th percentile)
- NVD status
- Modified
- Published
- 2006-02-19
CVE-2006-0785 at NVD
No indexed exploits for CVE-2006-0785 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2006-0785 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.