Lucene search

K
cveMitreCVE-2006-5284
HistoryOct 13, 2006 - 7:07 p.m.

CVE-2006-5284

2006-10-1319:07:00
mitre
web.nvd.nist.gov
27
cve-2006-5284
php
remote file inclusion
vulnerability
shen cheng-da
pnews

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.093

Percentile

94.7%

PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

Affected configurations

Nvd
Node
php_news_readerphp_news_readerRange2.6.4
OR
php_news_readerphp_news_readerMatch2.6.2
VendorProductVersionCPE
php_news_readerphp_news_reader*cpe:2.3:a:php_news_reader:php_news_reader:*:*:*:*:*:*:*:*
php_news_readerphp_news_reader2.6.2cpe:2.3:a:php_news_reader:php_news_reader:2.6.2:*:*:*:*:*:*:*

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.093

Percentile

94.7%

Related for CVE-2006-5284