Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2158

Опубликовано: 03 мая 2006
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stadtaus:guestbook_script:*:*:*:*:*:*:*:*
Версия до 1.7 (включая)

EPSS

Процентиль: 69%
0.00596
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.

EPSS

Процентиль: 69%
0.00596
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other