Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-1888

Опубликовано: 20 апр. 2006
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:phpgraphy:phpgraphy:*:*:*:*:*:*:*:*
Версия до 0.9.11 (включая)
cpe:2.3:a:phpgraphy:phpgraphy:0.9.9a:*:*:*:*:*:*:*
cpe:2.3:a:phpgraphy:phpgraphy:0.9.10:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01353
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this issue, since normal functionality allows the admin to modify pages.

EPSS

Процентиль: 80%
0.01353
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-264