5

CVE-2006-6112

Exploit
LifeType 1.0.x and 1.1.x have insufficient access control for all of the PHP scripts under (1) class/ and (2) plugins/, which allows remote attackers to obtain the installation path via a direct request to any of the scripts, as demonstrated by (a) bayesianfilter.class.php and (b) bootstrap.php, which leaks the path in an error message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LifetypeLifetype Version1.0.2
LifetypeLifetype Version1.0.3
LifetypeLifetype Version1.0.4
LifetypeLifetype Version1.0.5
LifetypeLifetype Version1.1.0
LifetypeLifetype Version1.1.1
LifetypeLifetype Version1.1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.76% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.