7.5

CVE-2006-6783

logahead UNU 1.0 before 20061226 allows remote attackers to upload arbitrary files via unspecified vectors related to plugins/widged/_widged.php (aka the WidgEd plugin), possibly because of an authentication bypass. NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LogaheadLogahead Unu Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.773
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://logahead.com/forums/comments.php?DiscussionID=216
http://secunia.com/advisories/23470
Vendor Advisory
http://securityreason.com/securityalert/2071
http://securitytracker.com/id?1017444
http://www.securityfocus.com/archive/1/455307/100/0/threaded
http://www.securityfocus.com/bid/21743
http://www.vupen.com/english/advisories/2006/5184
Vendor Advisory