CVE Database · CVE-2006-0899
CVSS v3.1
N/A
EPSS
9.76%
Published
Feb 27, 2006
Modified
Jun 16, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.
Affected Products (1)
References (18)