7.5

CVE-2006-3053

Exploit
PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter.  NOTE: this issue has been disputed by the vendor, who states "common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum."  CVE analysis concurs with the vendor
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhorumPhorum Version <= 5.1.13
PhorumPhorum Version3.1
PhorumPhorum Version3.1.1
PhorumPhorum Version3.1.1_pre
PhorumPhorum Version3.1.1_rc2
PhorumPhorum Version3.1.1a
PhorumPhorum Version3.1.2
PhorumPhorum Version3.2
PhorumPhorum Version3.2.2
PhorumPhorum Version3.2.3
PhorumPhorum Version3.2.3a
PhorumPhorum Version3.2.3b
PhorumPhorum Version3.2.4
PhorumPhorum Version3.2.5
PhorumPhorum Version3.2.6
PhorumPhorum Version3.2.7
PhorumPhorum Version3.2.8
PhorumPhorum Version3.3.1
PhorumPhorum Version3.3.1a
PhorumPhorum Version3.3.2
PhorumPhorum Version3.3.2a
PhorumPhorum Version3.3.2b3
PhorumPhorum Version3.4
PhorumPhorum Version3.4.1
PhorumPhorum Version3.4.2
PhorumPhorum Version3.4.3
PhorumPhorum Version3.4.4
PhorumPhorum Version3.4.5
PhorumPhorum Version3.4.6
PhorumPhorum Version3.4.7
PhorumPhorum Version3.4.8
PhorumPhorum Version3.4.8a
PhorumPhorum Version5.0.3_beta
PhorumPhorum Version5.0.7_beta
PhorumPhorum Version5.0.9
PhorumPhorum Version5.0.10
PhorumPhorum Version5.0.11
PhorumPhorum Version5.0.12
PhorumPhorum Version5.0.13
PhorumPhorum Version5.0.14
PhorumPhorum Version5.0.15a
PhorumPhorum Version5.0.16
PhorumPhorum Version5.0.17a
PhorumPhorum Version5.0.18
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.72% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.