7.5

CVE-2006-0478

CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php.  NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases.  We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cre LoadedCre Loaded Version6.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.08% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18648
Patch
Vendor Advisory
http://www.attrition.org/pipermail/vim/2006-February/000527.html
http://www.osvdb.org/22793
http://www.securityfocus.com/bid/16415
Patch
http://www.vupen.com/english/advisories/2006/0373
https://exchange.xforce.ibmcloud.com/vulnerabilities/24377