VulnerabilityModified
CVE-2006-5845
Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to 1.
MEDIUM 6.5EPSS 1.65%
Does this matter?
Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in index.php in Speedywiki 2.0 allows remote authenticated users to upload and execute arbitrary PHP code by setting the upload parameter to 1.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- speedywiki/speedywiki
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=116302805802656&w=2Mailing List
- http://s-a-p.ca/index.php?page=OurAdvisories&id=9Broken Link, URL Repurposed
- http://secunia.com/advisories/22788Permissions Required, Third Party Advisory
- http://securitytracker.com/id?1017201Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/4421Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30131
- http://marc.info/?l=bugtraq&m=116302805802656&w=2Mailing List
- http://s-a-p.ca/index.php?page=OurAdvisories&id=9Broken Link, URL Repurposed
- http://secunia.com/advisories/22788Permissions Required, Third Party Advisory
- http://securitytracker.com/id?1017201Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2006/4421Not Applicable
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30131
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.