[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

253928

 
 

909

 
 

198006

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-3615Date: (C)2006-07-18   (M)2023-12-22


Multiple PHP remote file inclusion vulnerabilities in Phorum 5.1.14, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via unspecified vectors related to an uninitialized variable.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.1
Exploit Score: 4.9
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
http://archives.neohapsis.com/archives/bugtraq/2006-07/0191.html
http://archives.neohapsis.com/archives/bugtraq/2006-07/0200.html
SECUNIA-21043
OSVDB-27164
OSVDB-27167
ADV-2006-2794
http://retrogod.altervista.org/phorum5_local_incl_xpl.html
http://www.phorum.org/phorum5/read.php?14%2C114358

CPE    1
cpe:/a:phorum:phorum:5.1.14

© SecPod Technologies