Lucene search

K
cve[email protected]CVE-2006-2005
HistoryApr 25, 2006 - 12:50 p.m.

CVE-2006-2005

2006-04-2512:50:00
web.nvd.nist.gov
21
cve-2006-2005
eval injection
clansys 1.1
remote attack
php code
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.168 Low

EPSS

Percentile

96.1%

Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an “include” statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.

Affected configurations

NVD
Node
clansysclansysMatch1.1
CPENameOperatorVersion
clansys:clansysclansyseq1.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

Low

0.168 Low

EPSS

Percentile

96.1%

Related for CVE-2006-2005