PoC Index

CVE-2006-6661

HIGH 7.5EPSS 6.6%

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
6.59% chance of exploitation in the next 30 days, 93th percentile
Published
2006-12-20
Updated
2024-08-07

ExploitDB entries (1)

References

Related