SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-5918

Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field.

HIGH 7.5EPSS 2.50%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the "Link to Download" field. NOTE: it is possible that the field value is restricted to files on specific public web sites.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.50% probability · 84th percentile
CISA KEV
Not listed
Affected
php rapid kill/php rapid kill
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.