Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6661

Опубликовано: 20 дек. 2006
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:php-update:php-update:*:*:*:*:*:*:*:*
Версия до 2.7 (включая)

EPSS

Процентиль: 87%
0.03263
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

EPSS

Процентиль: 87%
0.03263
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other