Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-6171

Опубликовано: 19 фев. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3

Описание

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

РелизСтатусПримечание
dapper

DNE

devel

DNE

gutsy

ignored

end of life, was needs-triage
hardy

released

5.7-1ubuntu1.2
intrepid

released

5.10-1ubuntu1.1
jaunty

not-affected

karmic

not-affected

upstream

released

5.15-1

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

gutsy

DNE

hardy

DNE

intrepid

DNE

jaunty

not-affected

karmic

not-affected

upstream

released

6.6-3

Показывать по

EPSS

Процентиль: 85%
0.02646
Низкий

9.3 Critical

CVSS2

Связанные уязвимости

nvd
больше 16 лет назад

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

debian
больше 16 лет назад

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, w ...

github
около 3 лет назад

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

EPSS

Процентиль: 85%
0.02646
Низкий

9.3 Critical

CVSS2