7.5
CVSSv2

CVE-2006-6417

Published: 10/12/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 up to and including 1.9 beta allows remote malicious users to execute arbitrary PHP code via a URL in the inc_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

b2evolution b2evolution 1.9_beta

b2evolution b2evolution 1.8.5

b2evolution b2evolution 1.9

Exploits

Severity: High Title: b2evolution Remote File inclusion Vulnerability Date: 281106 Author: tarkus (tarkus (at) tiifp (dot) org) Web: tiifporg/tarkus Vendor: b2evolution (b2evolutionnet/) Affected Product(s): b2evolution 185 - 19 beta - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Description: -- ...