Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-4733

Опубликовано: 13 сент. 2006
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sips:sips:*:*:*:*:*:*:*:*
Версия до 0.3.1 (включая)
cpe:2.3:a:sips:sips:0.2.2:*:*:*:*:*:*:*
cpe:2.3:a:sips:sips:0.2.4:*:*:*:*:*:*:*
cpe:2.3:a:sips:sips:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:sips:sips:0.3.0pl1:*:*:*:*:*:*:*
cpe:2.3:a:sips:sips:0.3.0pl2:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.1146
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.

EPSS

Процентиль: 93%
0.1146
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other