7.5

CVE-2006-1200

Exploit
Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.86% 0.765
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19154
Vendor Advisory
Exploit
http://www.securityfocus.com/archive/1/426932/100/0/threaded
http://www.vupen.com/english/advisories/2006/0885
http://securityreason.com/securityalert/553
http://www.osvdb.org/23750
http://www.securityfocus.com/bid/17004