7.5

CVE-2006-1959

PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ActualscriptsActualanalyzer Editionserver Version <= 8.23
ActualscriptsActualanalyzer Version2.72 Editionlite
ActualscriptsActualanalyzer Version7.63 Updategold
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.09% 0.959
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19743
http://securityreason.com/securityalert/742
http://securitytracker.com/id?1015967
http://www.osvdb.org/24778
http://www.securityfocus.com/archive/1/431351/100/0/threaded
http://www.securityfocus.com/archive/1/434562/100/0/threaded
http://www.securityfocus.com/bid/17597
http://www.vupen.com/english/advisories/2006/1430
https://exchange.xforce.ibmcloud.com/vulnerabilities/25893