2017-10-16 12:31:07 -04:00
|
|
|
{
|
2019-03-17 23:02:17 +00:00
|
|
|
"CVE_data_meta": {
|
|
|
|
"ASSIGNER": "cve@mitre.org",
|
|
|
|
"ID": "CVE-2006-2811",
|
|
|
|
"STATE": "PUBLIC"
|
|
|
|
},
|
|
|
|
"affects": {
|
|
|
|
"vendor": {
|
|
|
|
"vendor_data": [
|
|
|
|
{
|
|
|
|
"product": {
|
|
|
|
"product_data": [
|
|
|
|
{
|
|
|
|
"product_name": "n/a",
|
|
|
|
"version": {
|
|
|
|
"version_data": [
|
|
|
|
{
|
|
|
|
"version_value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"vendor_name": "n/a"
|
|
|
|
}
|
2017-10-16 12:31:07 -04:00
|
|
|
]
|
2019-03-17 23:02:17 +00:00
|
|
|
}
|
|
|
|
},
|
|
|
|
"data_format": "MITRE",
|
|
|
|
"data_type": "CVE",
|
|
|
|
"data_version": "4.0",
|
|
|
|
"description": {
|
|
|
|
"description_data": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
|
|
|
"value": "Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964."
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"problemtype": {
|
|
|
|
"problemtype_data": [
|
|
|
|
{
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "eng",
|
|
|
|
"value": "n/a"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"references": {
|
|
|
|
"reference_data": [
|
|
|
|
{
|
|
|
|
"name": "27223",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27223"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "ovidentia-multiple-scripts-file-include(26981)",
|
|
|
|
"refsource": "XF",
|
|
|
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26981"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27228",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27228"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27215",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27215"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27224",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27224"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27214",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27214"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "1033",
|
|
|
|
"refsource": "SREASON",
|
|
|
|
"url": "http://securityreason.com/securityalert/1033"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27216",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27216"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27212",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27212"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27222",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27222"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27221",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27221"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27226",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27226"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27220",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27220"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27225",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27225"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27211",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27211"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27229",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27229"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "18232",
|
|
|
|
"refsource": "BID",
|
|
|
|
"url": "http://www.securityfocus.com/bid/18232"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "20070114 Ovidentia 5.6x Series Remote File İnclude",
|
|
|
|
"refsource": "BUGTRAQ",
|
|
|
|
"url": "http://www.securityfocus.com/archive/1/456893/100/200/threaded"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27209",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27209"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27218",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27218"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27217",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27217"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27227",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27227"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27213",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27213"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "20060531 multiple file inclusion exploits in ovidentia v5.8.0",
|
|
|
|
"refsource": "BUGTRAQ",
|
|
|
|
"url": "http://www.securityfocus.com/archive/1/435590/100/0/threaded"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "27219",
|
|
|
|
"refsource": "OSVDB",
|
|
|
|
"url": "http://www.osvdb.org/27219"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"name": "20070209 Ovidentia Exploit Codeds",
|
|
|
|
"refsource": "BUGTRAQ",
|
|
|
|
"url": "http://www.securityfocus.com/archive/1/459572/100/0/threaded"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|