Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6255

Опубликовано: 04 дек. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nukeai:nukeai:0.0.3_beta:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.06244
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an AIML chatterbot, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension in the filename parameter and code in the moreinfo parameter, which is saved to a filename under descriptions/, which is accessible via a direct request.

EPSS

Процентиль: 90%
0.06244
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other