Vulnerability CVE-2006-2158


Published: 2006-05-03   Modified: 2012-02-12

Description:
Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.4/10
4.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Stadtaus -> Guestbook script 

 References:
http://www.vupen.com/english/advisories/2006/1660
http://www.stadtaus.com/forum/t-2600.html
http://retrogod.altervista.org/gbs_17_xpl_pl.html
http://xforce.iss.net/xforce/xfdb/26252
http://www.securityfocus.com/bid/17845
http://secunia.com/advisories/19957

Copyright 2024, cxsecurity.com

 

Back to Top