{"id":"CVE-2006-0847","aliases":["PYSEC-2006-1"],"url":"https://o3.security/vulnerability/CVE-2006-0847","summary":"CherryPy Directory traversal vulnerability","details":"Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via \"..\" sequences in unspecified vectors.","published":"2022-05-01T06:43:18Z","modified":"2024-09-13T18:02:35.908602Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"cherrypy","fixedVersion":"2.1.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0847"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24809"},{"type":"PACKAGE","url":"https://github.com/cherrypy/cherrypy"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cherrypy/PYSEC-2006-1.yaml"},{"type":"WEB","url":"https://web.archive.org/web/20140724140216/http://secunia.com/advisories/18944"},{"type":"WEB","url":"https://web.archive.org/web/20140803230356/http://secunia.com/advisories/20344"},{"type":"WEB","url":"https://web.archive.org/web/20200302050730/http://www.securityfocus.com/bid/16760"},{"type":"WEB","url":"http://groups.google.com/group/cherrypy-announce/browse_thread/thread/92b2972f774fe6df/2f63afc9433dc306#2f63afc9433dc306"},{"type":"WEB","url":"http://sourceforge.net/project/shownotes.php?release_id=384316&group_id=56099"},{"type":"WEB","url":"http://www.cherrypy.org"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-09-13T18:02:35.908602Z"}}