5.1
CVE-2006-2931
- EPSS 1.48%
- Veröffentlicht 21.06.2006 19:02:00
- Zuletzt bearbeitet 16.06.2026 22:26:03
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
CMS Mundo before 1.0 build 008 does not properly verify uploaded image files, which allows remote attackers to execute arbitrary PHP code by uploading and later directly accessing certain files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hotwebscripts ≫ Cms Mundo Version1.0
Hotwebscripts ≫ Cms Mundo Version1.0_build_007
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.48% | 0.705 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.1 | 4.9 | 6.4 |
AV:N/AC:H/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20362
http://secunia.com/secunia_research/2006-43/advisory/
http://securitytracker.com/id?1016311
http://www.securityfocus.com/archive/1/437183/100/200/threaded
http://www.vupen.com/english/advisories/2006/2348
http://www.osvdb.org/26465
https://exchange.xforce.ibmcloud.com/vulnerabilities/27094