SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-2033

PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter.

MEDIUM 6.4EPSS 2.17%

Does this matter?

Lower severity and a low EPSS score (2.17%). Track it; it rarely justifies an emergency change on its own.

Description

PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue.

CVSS 2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS
2.17% probability · 81th percentile
CISA KEV
Not listed
Affected
corenews/corenews
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.