1015429vdb entry
http://securitytracker.com/id?1015429 CVE-2006-0133
IBM AIX 5.3 - 'GetShell' / 'GetCommand' File Enumeration
Record summary
CVE-2006-0133 has a selected CVSS score of 3.6; EIP currently links 2 catalogued exploits.
Description
Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBIBM AIX 5.3 - 'GetShell' / 'GetCommand' File EnumerationExploitDB exploitby xfocusNot analyzed1 file
ExploitDBIBM AIX 5.3 - 'GetShell' / 'GetCommand' File DisclosureExploitDB exploitby xfocusNot analyzed1 file
References
520060101 [xfocus-SD-060101]AIX getCommand&getShell two vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/420589/100/0/threaded 16102vdb entry
http://www.securityfocus.com/bid/16102 16103vdb entry
http://www.securityfocus.com/bid/16103 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-0133