5
CVSSv2

CVE-2006-4877

Published: 19/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and previous versions allows remote malicious users to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) index.php, (2) profile.php, and (3) header.php.

Vulnerable Product Search on Vulmon Subscribe to Product

david bennett php-post

Exploits

source: wwwsecurityfocuscom/bid/20061/info PHP-Post is prone to multiple input-validation vulnerabilities, including multiple cross-site scripting, SQL-injection, and remote file-include issues, because the application fails to sanitize user-supplied input A successful exploit of these vulnerabilities could allow an attacker to comprom ...