5.1

CVE-2006-4191

Exploit
Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Xmb SoftwareExtreme Message Board Version <= 1.9.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.4% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://docs.xmbforum2.com/index.php?title=Security_Issue_History
http://secunia.com/advisories/21293
Vendor Advisory
Exploit
http://retrogod.altervista.org/xmb_196_sql.html
Exploit
http://securityreason.com/securityalert/1411
http://www.securityfocus.com/archive/1/443167/100/0/threaded
http://www.securityfocus.com/bid/19494
http://www.securityfocus.com/bid/19501
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/28356
https://www.exploit-db.com/exploits/2178