6.8

CVE-2006-5894

Exploit
Directory traversal vulnerability in lang.php in Rama CMS 0.68 and earlier, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by lang.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rama CmsRama Cms Version <= 0.68
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.51% 0.827
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/22847
Vendor Advisory
http://www.rahim.webd.pl/exploit127.html
Exploit
http://www.securityfocus.com/bid/21009
Exploit
http://www.vupen.com/english/advisories/2006/4473
https://exchange.xforce.ibmcloud.com/vulnerabilities/30183
https://www.exploit-db.com/exploits/2760