PoC Index

CVE-2006-0881

HIGH 7.5EPSS 7.7%

Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
7.65% chance of exploitation in the next 30 days, 94th percentile
Published
2006-02-24
Updated
2024-08-07

ExploitDB entries (1)

References

Related