CVE-2006-6740
- EPSS 11.4%
- Veröffentlicht 26.12.2006 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the i...
CVE-2006-6743
- EPSS 0.05%
- Veröffentlicht 26.12.2006 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
CVE-2006-6744
- EPSS 0.11%
- Veröffentlicht 26.12.2006 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts.
CVE-2006-5634
- EPSS 12.93%
- Veröffentlicht 01.11.2006 00:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc ...