CVE-2006-5596

AEP Smartgate 4.3b - Directory Traversal via HTTP GET Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5596. PoCs published by prdelka.

AI-analyzed exploit summary This exploit leverages a directory traversal vulnerability in AEP Smartgate's SSL server to download arbitrary files. It constructs a malicious HTTP GET request with traversal sequences to access files outside the web root.

Description

Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

Exploits (1)

exploitdb WORKING POC VERIFIED
by prdelka · cremotewindows
https://www.exploit-db.com/exploits/2637

This exploit leverages a directory traversal vulnerability in AEP Smartgate's SSL server to download arbitrary files. It constructs a malicious HTTP GET request with traversal sequences to access files outside the web root.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: AEP Smartgate V4.3B
No auth needed
Prerequisites: Network access to the target's SSL port (default 443) · OpenSSL library for SSL/TLS communication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22550
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4224
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29817
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2637
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20722

Scores

EPSS 0.0294
EPSS Percentile 85.3%

Details

Status published
Products (1)
aep_networks/smartgate_ssl_server 4.3b
Published Oct 28, 2006
Tracked Since Feb 18, 2026