Loading
Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing "/content".
Use Nullsoft vendor hub and Shoutcast Server product page to widen CVE-2006-3534 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2004-1373, CVE-2002-0907 and CVE-2002-0199 for nearby disclosures in the same product family.