6.4

CVE-2006-2158

Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StadtausGuestbook Script Version <= 1.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.6% 0.727
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://retrogod.altervista.org/gbs_17_xpl_pl.html
http://secunia.com/advisories/19957
http://www.securityfocus.com/bid/17845
http://www.stadtaus.com/forum/t-2600.html
http://www.vupen.com/english/advisories/2006/1660
https://exchange.xforce.ibmcloud.com/vulnerabilities/26252