CVE-2006-0707
Publication date 15 February 2006
Last updated 17 July 2025
Ubuntu priority
Description
PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.