CVE-2006-2100

Magic ISO Maker < 5.0_build_0166 - Directory Traversal and Arbitrary File Write via ISO Image Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2100. PoCs published by Sowhat.

AI-analyzed exploit summary The provided text describes a directory traversal vulnerability in MagicISO version 5.0 Build 0166, where malicious archives can be used to overwrite files on the target system. The exploit details are referenced from SecurityFocus and ExploitDB, but no actual exploit code is included.

Description

Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Sowhat · textremotewindows
https://www.exploit-db.com/exploits/27759

The provided text describes a directory traversal vulnerability in MagicISO version 5.0 Build 0166, where malicious archives can be used to overwrite files on the target system. The exploit details are referenced from SecurityFocus and ExploitDB, but no actual exploit code is included.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: MagicISO version 5.0 Build 0166
No auth needed
Prerequisites: Malicious archive file · User interaction to open the archive
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1568
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016007
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26140
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19864
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17725
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/815
Exploit, Vendor Advisory x_refsource_misc
http://secway.org/advisory/AD20060428.txt
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/432359/100/0/threaded

Scores

EPSS 0.0372
EPSS Percentile 88.4%

Details

Status published
Products (1)
magic_iso_maker/magic_iso_maker < 5.0_build_0166
Published Apr 29, 2006
Tracked Since Feb 18, 2026