Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-6957

Опубликовано: 29 янв. 2007
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:docebo:docebo:*:*:*:*:*:*:*:*
Версия до 3.0.3 (включая)

EPSS

Процентиль: 75%
0.00863
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

PHP remote file inclusion vulnerability in addons/mod_media/body.php in Docebo 3.0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[where_framework] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability. This issue is similar to CVE-2006-2576 and CVE-2006-3107, but the vectors are different.

EPSS

Процентиль: 75%
0.00863
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94