7.5
CVE-2006-1994
- EPSS 3.44%
- Veröffentlicht 25.04.2006 12:50:00
- Zuletzt bearbeitet 16.06.2026 22:24:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.44% | 0.874 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html
http://secunia.com/advisories/19788
http://www.nukedx.com/?viewdoc=27
http://www.securityfocus.com/archive/1/431758
http://www.securityfocus.com/bid/17650
http://www.vupen.com/english/advisories/2006/1482
https://exchange.xforce.ibmcloud.com/vulnerabilities/26035