7.5

CVE-2005-4135

Exploit
Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SimplemediaSimplebbs Version1.0.6
SimplemediaSimplebbs Version1.0.7
SimplemediaSimplebbs Version1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.62% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/17949
Vendor Advisory
http://securitytracker.com/id?1015323
http://www.securityfocus.com/archive/1/418838/100/0/threaded
http://www.securityfocus.com/bid/15764
Exploit
http://www.vupen.com/english/advisories/2005/2807