6.8
CVE-2006-6511
- EPSS 1.17%
- Veröffentlicht 14.12.2006 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.632 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://bugs.dadaimc.org/view.php?id=191
http://secunia.com/advisories/23305
http://www.vupen.com/english/advisories/2006/4977
https://exchange.xforce.ibmcloud.com/vulnerabilities/30862