7.5

CVE-2006-7006

Exploit
PHP remote file inclusion vulnerability in upload/admin/team.php in Robin de Graff Somery 0.4.4 allows remote attackers to execute arbitrary PHP code via a URL in the checkauth parameter.  NOTE: CVE disputes this vulnerability because the checkauth parameter is only used in conditionals
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Robin De GraffSomery Version0.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.9% 0.77
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/bugtraq/2006-06/0242.html
http://packetstorm.linuxsecurity.com/0606-exploits/Somery.txt
http://www.attrition.org/pipermail/vim/2007-February/001305.html
http://www.osvdb.org/27662
http://www.root-security.org/danger/Somery.txt
Exploit
URL Repurposed
http://www.securityfocus.com/bid/18412