CVE-2006-6661
HIGH 7.5EPSS 6.6%
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 6.59% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2006-12-20
- Updated
- 2024-08-07