7.5

CVE-2006-0147

Exploit

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.

Data is provided by the National Vulnerability Database (NVD)
John LimAdodb Version4.66
John LimAdodb Version4.68
MantisMantis Version0.19.4
MantisMantis Version1.0.0_rc4
MoodleMoodle Version1.5.3
The Cacti GroupCacti Version0.8.6g
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 21.17% 0.951
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
http://secunia.com/advisories/17418
Patch
Vendor Advisory
Exploit