CVE-2006-2406

Unclassified Newsboard < 1.5.3d - Path Traversal

Title source: rule

Description

Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is closely related, but a different vulnerability than the ABBC[Config][smileset] parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1777

Scores

EPSS 0.0336
EPSS Percentile 87.4%

Details

Status published
Products (1)
unclassified_newsboard/unclassified_newsboard < 1.5.3d
Published May 16, 2006
Tracked Since Feb 18, 2026