SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-3584

Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.

HIGH 7.5EPSS 1.55%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Dynamic variable evaluation vulnerability in index.php in Jetbox CMS 2.1 SR1 allows remote attackers to overwrite configuration variables via URL parameters, which are evaluated as PHP variable variables.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.55% probability · 74th percentile
CISA KEV
Not listed
Affected
jetbox/jetbox cms
Source
PSIRT-CNA@flexerasoftware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.