7.5
CVE-2006-1959
- EPSS 13.09%
- Veröffentlicht 21.04.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Actualscripts ≫ Actualanalyzer Editionserver Version <= 8.23
Actualscripts ≫ Actualanalyzer Version2.72 Editionlite
Actualscripts ≫ Actualanalyzer Version7.63 Updategold
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 13.09% | 0.959 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/19743
http://securityreason.com/securityalert/742
http://securitytracker.com/id?1015967
http://www.osvdb.org/24778
http://www.securityfocus.com/archive/1/431351/100/0/threaded
http://www.securityfocus.com/archive/1/434562/100/0/threaded
http://www.securityfocus.com/bid/17597
http://www.vupen.com/english/advisories/2006/1430
https://exchange.xforce.ibmcloud.com/vulnerabilities/25893