Lucene search

K
nvd[email protected]NVD:CVE-2006-2860
HistoryJun 06, 2006 - 8:06 p.m.

CVE-2006-2860

2006-06-0620:06:00
CWE-94
web.nvd.nist.gov

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.3%

PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php. NOTE: some of these vectors were also reported for 3.0 in a separate disclosure.

Affected configurations

NVD
Node
webspotwebspotbloggingMatch3.0
OR
webspotwebspotbloggingMatch3.0.1

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.026 Low

EPSS

Percentile

90.3%

Related for NVD:CVE-2006-2860