Lucene search

K
cveMitreCVE-2006-5310
HistoryOct 17, 2006 - 4:07 p.m.

CVE-2006-5310

2006-10-1716:07:00
CWE-94
mitre
web.nvd.nist.gov
43
php
remote file inclusion
vulnerability
j-pierre dezelus
phpmyconferences
phpmyconference
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0.092

Percentile

94.7%

PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.

Affected configurations

Nvd
Node
j-pierre_dezelusles_visiteursMatch2.0.1
OR
phpmyconferencesphpmyconferencesRange8.0.2
VendorProductVersionCPE
j-pierre_dezelusles_visiteurs2.0.1cpe:2.3:a:j-pierre_dezelus:les_visiteurs:2.0.1:*:*:*:*:*:*:*
phpmyconferencesphpmyconferences*cpe:2.3:a:phpmyconferences:phpmyconferences:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

High

EPSS

0.092

Percentile

94.7%

Related for CVE-2006-5310