5

CVE-2006-0891

Exploit
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NoccNocc Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.3% 0.942
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html
Exploit
http://retrogod.altervista.org/noccw_10_incl_xpl.html
http://secunia.com/advisories/16921
Vendor Advisory
http://securitytracker.com/id?1015671
http://www.osvdb.org/23416
http://www.osvdb.org/23417
http://www.osvdb.org/23418
http://www.osvdb.org/23419
http://www.securityfocus.com/bid/16793
https://exchange.xforce.ibmcloud.com/vulnerabilities/24934