7.5
CVSSv2

CVE-2006-6966

Published: 04/02/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

phpGraphy prior to 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote malicious users to execute arbitrary PHP code by uploading a config.php file via the pictures[] parameter to index.php. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpGraphy.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgraphy phpgraphy 0.9

phpgraphy phpgraphy 0.9.1

phpgraphy phpgraphy 0.9.4

phpgraphy phpgraphy 0.9.5

phpgraphy phpgraphy 0.9.11

phpgraphy phpgraphy 0.9.12

phpgraphy phpgraphy 0.9.8

phpgraphy phpgraphy 0.9.9

phpgraphy phpgraphy 0.9.2

phpgraphy phpgraphy 0.9.3

phpgraphy phpgraphy 0.9.9a

phpgraphy phpgraphy

phpgraphy phpgraphy 0.9.10

phpgraphy phpgraphy 0.9.10a

phpgraphy phpgraphy 0.9.6

phpgraphy phpgraphy 0.9.7

Exploits

<?php print_r(' --------------------------------------------------------------------------- PHPGraphy 0912 Zend_Hash_Del_Key_Or_Index/privilege escalation/ /remote command execution exploit by rgod dork: intext:"This site is using phpGraphy" | intitle:"my phpgraphy site" mail: retrog@aliceit site: retrogodaltervistaorg -------------- ...