Lucene search

K
cve[email protected]CVE-2006-1819
HistoryApr 18, 2006 - 10:02 a.m.

CVE-2006-1819

2006-04-1810:02:00
web.nvd.nist.gov
33
cve
2006
1819
phpwebsite
vulnerability
remote attackers
arbitrary local files
php code
directory traversal

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.4%

Directory traversal vulnerability in the loadConfig function in index.php in phpWebSite 0.10.2 and earlier allows remote attackers to include arbitrary local files and execute arbitrary PHP code via the hub_dir parameter, as demonstrated by including access_log. NOTE: in some cases, arbitrary remote file inclusion could be performed under PHP 5 using an SMB share argument such as “\systemname\sharename”.

Affected configurations

NVD
Node
phpwebsitephpwebsiteRange0.10.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.4%