CVE-2006-0244

phpXplorer 0.9.33 - Directory Traversal via sShare Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0244. PoCs published by Oriol Torrent Santiago.

AI-analyzed exploit summary The exploit describes a directory traversal vulnerability in phpXplorer due to improper input sanitization. An attacker can retrieve arbitrary files by manipulating the `sShare` parameter in the URL.

Description

Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root

Exploits (1)

exploitdb WRITEUP VERIFIED
by Oriol Torrent Santiago · textwebappsphp
https://www.exploit-db.com/exploits/27097

The exploit describes a directory traversal vulnerability in phpXplorer due to improper input sanitization. An attacker can retrieve arbitrary files by manipulating the `sShare` parameter in the URL.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: phpXplorer 0.9.33
No auth needed
Prerequisites: Access to the vulnerable phpXplorer instance
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/422158/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39982
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16263
Exploit, Vendor Advisory x_refsource_misc
http://www.arrelnet.com/advisories/adv20060116.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0232
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18518
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/353
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/421997/100/0/threaded

Scores

EPSS 0.0313
EPSS Percentile 86.6%

Details

Status published
Products (1)
phpxplorer/phpxplorer 0.9.33
Published Jan 18, 2006
Tracked Since Feb 18, 2026