5.1

CVE-2006-3193

Exploit
Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2) addbioform.php, (3) addfliersform.php, (4) addgenmerchform.php, (5) addinterviewsform.php, (6) addlinksform.php, (7) addlyricsform.php, (8) addmembioform.php, (9) addmerchform.php, (10) addmerchpicform.php, (11) addnewsform.php, (12) addphotosform.php, (13) addreleaseform.php, (14) addreleasepicform.php, (15) addrelmerchform.php, (16) addreviewsform.php, (17) addshowsform.php, (18) addwearmerchform.php; (19) adminpanel/includes/mailinglist/disphtmltbl.php, and (20) adminpanel/includes/mailinglist/dispxls.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrayscaleBandsite Cms Version1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 14.58% 0.962
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://secunia.com/advisories/20768
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=428062
http://www.osvdb.org/27233
http://www.osvdb.org/27234
http://www.osvdb.org/27235
http://www.osvdb.org/27236
http://www.osvdb.org/27237
http://www.osvdb.org/27238
http://www.osvdb.org/27239
http://www.osvdb.org/27240
Exploit
http://www.osvdb.org/27241
Exploit
http://www.osvdb.org/27242
Exploit
http://www.osvdb.org/27243
Exploit
http://www.osvdb.org/27244
Exploit
http://www.osvdb.org/27245
Exploit
http://www.osvdb.org/27246
http://www.osvdb.org/27247
Exploit
http://www.osvdb.org/27248
Exploit
http://www.osvdb.org/27249
Exploit
http://www.osvdb.org/27250
Exploit
http://www.osvdb.org/27251
Exploit
http://www.osvdb.org/27252
Exploit
http://www.securityfocus.com/bid/18555
http://www.vupen.com/english/advisories/2006/2462
Vendor Advisory
https://www.exploit-db.com/exploits/1933