5

CVE-2006-0713

Exploit
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php.  NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LinphaLinpha Version0.9.0
LinphaLinpha Version0.9.1
LinphaLinpha Version0.9.2
LinphaLinpha Version0.9.3
LinphaLinpha Version0.9.4
LinphaLinpha Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.02% 0.857
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://retrogod.altervista.org/linpha_10_local.html
Exploit
http://secunia.com/advisories/18808
Vendor Advisory
http://securityreason.com/securityalert/426
http://www.securityfocus.com/archive/1/424729/100/0/threaded
http://www.securityfocus.com/bid/16592
Exploit
http://www.vupen.com/english/advisories/2006/0535
https://exchange.xforce.ibmcloud.com/vulnerabilities/24663