PoC Index

CVE-2006-4311

HIGH 7.5EPSS 3.2%

PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote attackers to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
3.18% chance of exploitation in the next 30 days, 87th percentile
Published
2006-08-23
Updated
2024-08-07

ExploitDB entries (1)

References

Related