5.1
CVSSv2

CVE-2006-3361

Published: 06/07/2006 Updated: 20/07/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and previous versions, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP parameter in studip-htdocs/archiv_assi.php.

Vulnerable Product Search on Vulmon Subscribe to Product

stud.ip stud.ip

Exploits

/*------------------------------------------------ IHS Public advisory -------------------------------------------------*/ StudIP Remote File Inclusion StudIP is a learning and an information management system for universities, educational facilities and enterprises wwwstudipde wwwdata-questde wwwsource ...