CVE-2006-5763

⚪ Do wiadomości

Wielokrotne luki w zdalnym dołączaniu plików w Free File Hosting umożliwiają wykonanie dowolnego kodu PHP.

CVSS
5.1
EPSS
16.7%
Exploit
none
Vendor
free_php_scripts
Opis źródłowy (NVD)

Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter to (1) login.php, (2) register.php, or (3) send.php. NOTE: the original provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. Vector 1 also affects Free Image Hosting 2.0, which contains the same code.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)16.7%
Opublikowano (NVD)2006-11-06 23:07:00 UTC
Ostatnia modyfikacja (NVD)2026-04-23 00:35:47 UTC
Referencje