CVE-2006-0847

CherryPy < 2.1.1 - Directory Traversal via Staticfilter Component

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors.

References (9)

Core 9
Core References
Various Sources x_refsource_confirm
http://www.cherrypy.org/
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16760
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18944
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20344
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0677
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200605-16.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24809

Scores

EPSS 0.0233
EPSS Percentile 81.7%

Details

Status published
Products (23)
cherrypy/cherrypy 0.1
cherrypy/cherrypy 0.2
cherrypy/cherrypy 0.3
cherrypy/cherrypy 0.4
cherrypy/cherrypy 0.5
cherrypy/cherrypy 0.6
cherrypy/cherrypy 0.7
cherrypy/cherrypy 0.8
cherrypy/cherrypy 0.8_beta
cherrypy/cherrypy 0.9
... and 13 more
Published Feb 22, 2006
Tracked Since Feb 18, 2026