Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6511

Опубликовано: 14 дек. 2006
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dadaimc:dadaimc:*:*:*:*:*:*:*:*
Версия до 0.99.3 (включая)

EPSS

Процентиль: 75%
0.00855
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

dadaIMC .99.3 uses an insufficiently restrictive FilesMatch directive in the installed .htaccess file, which allows remote attackers to execute arbitrary PHP code by uploading files whose names contain (1) feature, (2) editor, (3) newswire, (4) otherpress, (5) admin, (6) pbook, (7) media, or (8) mod, which are processed as PHP file types (application/x-httpd-php).

EPSS

Процентиль: 75%
0.00855
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other