7.5

CVE-2006-0824

Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GeeklogGeeklog Version1.3.11
GeeklogGeeklog Version1.3.11_sr1
GeeklogGeeklog Version1.3.11_sr2
GeeklogGeeklog Version1.3.11_sr3
GeeklogGeeklog Version1.4.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.06% 0.859
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/18920
Patch
Vendor Advisory
http://www.geeklog.net/article.php/geeklog-1.4.0sr1
Patch
http://www.gulftech.org/?node=research&article_id=00102-02192006
http://www.securityfocus.com/archive/1/425506/100/0/threaded
http://www.securityfocus.com/bid/16755
http://www.vupen.com/english/advisories/2006/0661
http://www.osvdb.org/23349