5.1

CVE-2006-2608

Exploit
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as demonstrated by injecting PHP code into info.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.64% 0.836
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20204
Vendor Advisory
http://securityreason.com/securityalert/957
http://www.securityfocus.com/archive/1/434738/100/0/threaded
http://www.securityfocus.com/bid/18047
Exploit
http://www.vupen.com/english/advisories/2006/1930
https://exchange.xforce.ibmcloud.com/vulnerabilities/26597