6.8

CVE-2006-5048

Exploit
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php, (2) lang.php, (3) client.php, and (4) server.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WaltercedricCom Securityimages Version <= 3.0.5
WaltercedricCom Securityimages Version2.2.5
WaltercedricCom Securityimages Version2.2.6
WaltercedricCom Securityimages Version3.00 Updaterc1
WaltercedricCom Securityimages Version3.0.3
WaltercedricCom Securityimages Version3.0.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.51% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://forum.joomla.org/index.php/topic%2C79477.0.html
http://forum.joomla.org/index.php/topic%2C81589.0.html
http://secunia.com/advisories/21260
Patch
Vendor Advisory
Exploit
http://www.osvdb.org/27655
http://www.osvdb.org/27656
http://www.osvdb.org/27657
http://www.osvdb.org/27658
http://www.securityfocus.com/bid/19217
http://www.vupen.com/english/advisories/2006/3062
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/28078
https://www.exploit-db.com/exploits/2083