Unrated severityNVD Advisory· Published Apr 25, 2006· Updated Apr 16, 2026
CVE-2006-1995
CVE-2006-1995
Description
Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.
Affected products
1- cpe:2.3:a:scry_gallery:scry_gallery:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- downloads.securityfocus.com/vulnerabilities/exploits/17649-directory-traversal.exploitnvdExploit
- www.securityfocus.com/bid/17649nvdExploit
- attrition.org/pipermail/vim/2006-April/000716.htmlnvd
- secunia.com/advisories/19777nvd
- securityreason.com/securityalert/784nvd
- www.osvdb.org/24889nvd
- www.securityfocus.com/archive/1/431716/100/0/threadednvd
- www.securityfocus.com/bid/17668nvd
- www.vupen.com/english/advisories/2006/1490nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25991nvd
News mentions
0No linked articles in our index yet.