CVE-2006-7080
MEDIUM 4.3EPSS 4.5%
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter.
- CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 4.49% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2007-02-27
- Updated
- 2024-08-07