7.5

CVE-2006-1243

Exploit
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Alexander PalmoSimple Php Blog Version <= 0.4.7.1
Alexander PalmoSimple Php Blog Version0.4.0
Alexander PalmoSimple Php Blog Version0.4.5
Alexander PalmoSimple Php Blog Version0.4.6
Alexander PalmoSimple Php Blog Version0.4.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.53% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19270
http://sourceforge.net/forum/forum.php?forum_id=564904
http://www.attrition.org/pipermail/vim/2006-November/001138.html
http://www.securityfocus.com/bid/17102
Exploit
http://www.vupen.com/english/advisories/2006/1007
https://exchange.xforce.ibmcloud.com/vulnerabilities/25322
https://www.exploit-db.com/exploits/1581