René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

87 lines
2.7 KiB
JSON

{
"id": "CVE-2006-5918",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-11-15T15:07:00.000",
"lastModified": "2018-10-17T21:45:55.843",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Unrestricted file upload vulnerability in RapidKill (aka PHP Rapid Kill) 5.7 Pro, and certain other versions, allows remote attackers to upload and execute arbitrary PHP scripts via the \"Link to Download\" field. NOTE: it is possible that the field value is restricted to files on specific public web sites."
},
{
"lang": "es",
"value": "Vulnerabilidad en transmisi\u00f3n de archivos no restrictivos en RapidKill (tambi\u00e9n conocido c\u00f3mo PHP Rapid Kill) 5.7 Pro, y otras ciertas versiones, permite a un atacante actualizar y ejecutar secuencias de comandos PHP de su elecci\u00f3n a trav\u00e9s del campo \"Link to Download\". NOTA: es posible que el campo valor est\u00e9 restringido a archivos sobre sitios web p\u00fablicos espec\u00edficos."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php_rapid_kill:php_rapid_kill:5.7_pro:*:*:*:*:*:*:*",
"matchCriteriaId": "91AD875E-B4A1-4E24-82EB-AA4DD23A34FC"
}
]
}
]
}
],
"references": [
{
"url": "http://securityreason.com/securityalert/1862",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/450681/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20896",
"source": "cve@mitre.org"
}
]
}