CVE-2006-1243
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 9.75% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- alexander palmo/simple php blog
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19270
- http://sourceforge.net/forum/forum.php?forum_id=564904
- http://www.attrition.org/pipermail/vim/2006-November/001138.html
- http://www.securityfocus.com/bid/17102Exploit
- http://www.vupen.com/english/advisories/2006/1007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25322
- https://www.exploit-db.com/exploits/1581
- http://secunia.com/advisories/19270
- http://sourceforge.net/forum/forum.php?forum_id=564904
- http://www.attrition.org/pipermail/vim/2006-November/001138.html
- http://www.securityfocus.com/bid/17102Exploit
- http://www.vupen.com/english/advisories/2006/1007
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25322
- https://www.exploit-db.com/exploits/1581
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.