Unrated severityNVD Advisory· Published Sep 19, 2006· Updated Apr 16, 2026
CVE-2006-4878
CVE-2006-4878
Description
Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to affect 1.0.1, and demonstrated for code execution by uploading and accessing an avatar file.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- secunia.com/advisories/22014nvd
- securityreason.com/securityalert/1607nvd
- www.osvdb.org/28964nvd
- www.securityfocus.com/archive/1/446318/100/0/threadednvd
- www.securityfocus.com/bid/20061nvd
- www.securityfocus.com/bid/20616nvd
- www.vupen.com/english/advisories/2006/3688nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29673nvd
- www.exploit-db.com/exploits/2593nvd
News mentions
0No linked articles in our index yet.