CVE-2006-0707

Publication date 15 February 2006

Last updated 17 July 2025


Ubuntu priority

Description

PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP request with multiple leading / (slash) characters, which is accessed using the PATH_INFO variable.

Status

Package Ubuntu Release Status
pyblosxom 9.10 karmic
Fixed 1.3.2-1
9.04 jaunty
Fixed 1.3.2-1
8.10 intrepid
Fixed 1.3.2-1
8.04 LTS hardy
Fixed 1.3.2-1
7.10 gutsy
Fixed 1.3.2-1
7.04 feisty
Fixed 1.3.2-1
6.10 edgy
Fixed 1.3.2-1
6.06 LTS dapper Ignored end of life