CVE-2006-0847: CherryPy Directory traversal vulnerability
(updated )
Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via “..” sequences in unspecified vectors.
References
- exchange.xforce.ibmcloud.com/vulnerabilities/24809
- github.com/advisories/GHSA-vx77-5pf4-c9wr
- github.com/cherrypy/cherrypy
- github.com/pypa/advisory-database/tree/main/vulns/cherrypy/PYSEC-2006-1.yaml
- nvd.nist.gov/vuln/detail/CVE-2006-0847
- web.archive.org/web/20140724140216/http://secunia.com/advisories/18944
- web.archive.org/web/20140803230356/http://secunia.com/advisories/20344
- web.archive.org/web/20200302050730/http://www.securityfocus.com/bid/16760
Detect and mitigate CVE-2006-0847 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →