6.4
CVSSv2

CVE-2006-1584

Published: 02/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote malicious users to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juliusz julas gonera warcraft iii replay parser php 1.8c

Exploits

source: wwwsecurityfocuscom/bid/17334/info Warcraft III Replay Parser for PHP is prone to a remote file-include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in t ...