7.5
CVE-2006-4311
- EPSS 3.17%
- Veröffentlicht 23.08.2006 19:04:00
- Zuletzt bearbeitet 16.06.2026 22:28:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonium ≫ Enterprise Adressbook Version0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.17% | 0.864 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/21553
http://www.bb-pcsecurity.de/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_0.2_%28folder%29_RFI.htm
http://www.securityfocus.com/archive/1/443701/100/0/threaded
http://www.securityfocus.com/bid/19597
http://www.vupen.com/english/advisories/2006/3334
https://exchange.xforce.ibmcloud.com/vulnerabilities/28464