Vulnerability Details CVE-2006-2698
Geeklog 1.4.0sr2 and earlier allows remote attackers to obtain the full installation path via a direct request and possibly invalid arguments to (1) layout/professional/functions.php or (2) getimage.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.0%
CVSS Severity
CVSS v2 Score 7.8
Products affected by CVE-2006-2698
-
cpe:2.3:a:geeklog:geeklog:1.3
-
cpe:2.3:a:geeklog:geeklog:1.3.0
-
cpe:2.3:a:geeklog:geeklog:1.3.10
-
cpe:2.3:a:geeklog:geeklog:1.3.10_rc1
-
cpe:2.3:a:geeklog:geeklog:1.3.10_rc2
-
cpe:2.3:a:geeklog:geeklog:1.3.10_rc3
-
cpe:2.3:a:geeklog:geeklog:1.3.11
-
cpe:2.3:a:geeklog:geeklog:1.3.11_rc1
-
cpe:2.3:a:geeklog:geeklog:1.3.11_sr1
-
cpe:2.3:a:geeklog:geeklog:1.3.11_sr2
-
cpe:2.3:a:geeklog:geeklog:1.3.11_sr3
-
cpe:2.3:a:geeklog:geeklog:1.3.11_sr4
-
cpe:2.3:a:geeklog:geeklog:1.3.5
-
cpe:2.3:a:geeklog:geeklog:1.3.5_sr1
-
cpe:2.3:a:geeklog:geeklog:1.3.6
-
cpe:2.3:a:geeklog:geeklog:1.3.7
-
cpe:2.3:a:geeklog:geeklog:1.3.7_sr1
-
cpe:2.3:a:geeklog:geeklog:1.3.7_sr2
-
cpe:2.3:a:geeklog:geeklog:1.3.7_sr3
-
cpe:2.3:a:geeklog:geeklog:1.3.7_sr4
-
cpe:2.3:a:geeklog:geeklog:1.3.7_sr5
-
cpe:2.3:a:geeklog:geeklog:1.3.8
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr1
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr2
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr3
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr4
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr5
-
cpe:2.3:a:geeklog:geeklog:1.3.8_1_sr6
-
cpe:2.3:a:geeklog:geeklog:1.3.9
-
cpe:2.3:a:geeklog:geeklog:1.3.9_rc1
-
cpe:2.3:a:geeklog:geeklog:1.3.9_rc2
-
cpe:2.3:a:geeklog:geeklog:1.3.9_rc3
-
cpe:2.3:a:geeklog:geeklog:1.3.9_sr1
-
cpe:2.3:a:geeklog:geeklog:1.3.9_sr2
-
cpe:2.3:a:geeklog:geeklog:1.3.9_sr3
-
cpe:2.3:a:geeklog:geeklog:1.3.9_sr4
-
cpe:2.3:a:geeklog:geeklog:1.35
-
cpe:2.3:a:geeklog:geeklog:1.4.0
-
cpe:2.3:a:geeklog:geeklog:1.4.0_beta1
-
cpe:2.3:a:geeklog:geeklog:1.4.0_sr1