Vulnerability CVE-2005-4135


Published: 2005-12-09   Modified: 2012-02-12

Description:
Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php.

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Simplemedia -> Simplebbs 

 References:
http://securitytracker.com/id?1015323
http://www.securityfocus.com/archive/1/418838/100/0/threaded
http://www.securityfocus.com/bid/15764
http://www.vupen.com/english/advisories/2005/2807

Copyright 2024, cxsecurity.com

 

Back to Top