Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
Loading...
Loading...
Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
March 12, 2006
April 16, 2026
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
Easy File Sharing Web Server 3.2 - Full Path Request Arbitrary File Upload
Open source ↗See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-1161
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.