6.4

CVE-2006-2331

Exploit
Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (dot dot) in the settings[locale] parameter in infusions/last_seen_users_panel/last_seen_users_panel.php, and (2) a ..  (dot dot) in the localeset parameter in setup.php.  NOTE: the vendor states that this issue might exist due to problems in third party local files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php FusionPhp Fusion Version6.00.3
Php FusionPhp Fusion Version6.00.105
Php FusionPhp Fusion Version6.00.106
Php FusionPhp Fusion Version6.00.107
Php FusionPhp Fusion Version6.00.109
Php FusionPhp Fusion Version6.00.110
Php FusionPhp Fusion Version6.00.204
Php FusionPhp Fusion Version6.00.206
Php FusionPhp Fusion Version6.00.303
Php FusionPhp Fusion Version6.00.304
Php FusionPhp Fusion Version6.00.306
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.36% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19992
Patch
http://securityreason.com/securityalert/873
http://www.php-fusion.co.uk/news.php
Patch
http://www.securityfocus.com/archive/1/433277/100/0/threaded
http://www.securityfocus.com/bid/17898
Exploit
http://www.vupen.com/english/advisories/2006/1735
http://securityreason.com/securityalert/194
http://www.osvdb.org/25538
http://www.osvdb.org/25539
http://www.php-fusion.co.uk/news.php?readmore=321
Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/26389