Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4631

Опубликовано: 08 сент. 2006
Источник: nvd
CVSS2: 6.5
EPSS Средний

Описание

Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:softbb:softbb:*:*:*:*:*:*:*:*
Версия до 0.1 (включая)

EPSS

Процентиль: 94%
0.13282
Средний

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

EPSS

Процентиль: 94%
0.13282
Средний

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other