7.5

CVE-2006-3158

Exploit
index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.12% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20731
Vendor Advisory
http://www.biyosecurity.be/bugs/meeting.txt
http://www.osvdb.org/26627
http://www.securityfocus.com/archive/1/437992/100/0/threaded
http://www.securityfocus.com/bid/18499
Exploit
http://www.vupen.com/english/advisories/2006/2428
https://exchange.xforce.ibmcloud.com/vulnerabilities/27296