CVE-2006-7079
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.85% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-913
- Affected
- exv2/content management system
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/20161Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29116Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/2415Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/20161Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29116Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/2415Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.