CVE-2006-7036
PHP remote file inclusion vulnerability in register.php for Andys Chat 4.5 allows remote attackers to execute arbitrary code via the action parameter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
PHP remote file inclusion vulnerability in register.php for Andys Chat 4.5 allows remote attackers to execute arbitrary code via the action parameter. NOTE: this issue was announced by an unreliable researcher, but the vendor is no longer distributing the product, so the original claims can not be evaluated.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.78% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- andys chat/andys chat
- Source
- cve@mitre.org
References
- http://securityreason.com/securityalert/2284
- http://www.securityfocus.com/archive/1/437300/30/4350/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27187
- http://securityreason.com/securityalert/2284
- http://www.securityfocus.com/archive/1/437300/30/4350/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27187
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.