Lucene search

K
cveMitreCVE-2006-2877
HistoryJun 07, 2006 - 12:02 a.m.

CVE-2006-2877

2006-06-0700:02:00
mitre
web.nvd.nist.gov
26
cve-2006-2877
php
remote file inclusion
vulnerability
bookmark4u 2.0.0
inc/dbase.php
inc/config.php
inc/common.php
inc/function.php
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.584

Percentile

97.7%

PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.

Affected configurations

Nvd
Node
sangwan_kimbookmark4uRange2.0
VendorProductVersionCPE
sangwan_kimbookmark4u*cpe:2.3:a:sangwan_kim:bookmark4u:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

High

EPSS

0.584

Percentile

97.7%

Related for CVE-2006-2877