7.5
CVE-2006-0206
- EPSS 4.18%
- Veröffentlicht 13.01.2006 23:03:00
- Zuletzt bearbeitet 16.06.2026 22:20:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Light Weight Calendar ≫ Light Weight Calendar Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.18% | 0.896 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://attrition.org/pipermail/vim/2006-March/000612.html
http://evuln.com/vulns/29/exploit.html
http://evuln.com/vulns/29/summary.html
http://secunia.com/advisories/18450
http://www.osvdb.org/22376
http://www.securityfocus.com/archive/1/421920
http://www.securityfocus.com/bid/16229
http://www.vupen.com/english/advisories/2006/0171
https://exchange.xforce.ibmcloud.com/vulnerabilities/24110