7.5
CVE-2006-0169
- EPSS 1.86%
- Veröffentlicht 11.01.2006 21:03:00
- Zuletzt bearbeitet 16.06.2026 22:20:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
addresses.php3 in MyPhPim 01.05 does not restrict uploaded files, which allows remote attackers to execute arbitrary PHP code via the pdbfile variable, then directly accessing those files from the uploads directory.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.86% | 0.765 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/18399
http://www.vupen.com/english/advisories/2006/0147
http://evuln.com/vulns/23/summary.html
http://www.securityfocus.com/archive/1/421626/100/0/threaded
http://www.securityfocus.com/bid/16208
https://exchange.xforce.ibmcloud.com/vulnerabilities/24070