CVE-2006-6376

Simple File Manager 0.24a - Path Traversal

Title source: llm
STIX 2.1

Description

Multiple directory traversal vulnerabilities in fm.php in Simple File Manager (SFM) 0.24a allow remote attackers to use ".." sequences to (1) read arbitrary files via the filename parameter in a download action, (2) delete arbitrary files via the delete parameter, and (3) modify arbitrary files via the edit parameter, which can be leveraged to execute arbitrary code.

Exploits (1)

exploitdb WRITEUP VERIFIED
by flame · textwebappsphp
https://www.exploit-db.com/exploits/2883

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30687
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2883

Scores

EPSS 0.1511
EPSS Percentile 94.7%

Details

Status published
Products (1)
onedotoh/simple_file_manager 0.24a
Published Dec 07, 2006
Tracked Since Feb 18, 2026