Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2006-5137

EPSS 3.17% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2006-5137

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code via a config[] array parameter to admin/doeditconfig.php, and then execute the code via includes/config.inc.php; and inject a reference to PHP code via a URL in the config[path] parameter, and then execute the code via (3) dorateuser.php, (4) calendar.php, and unspecified other scripts.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
UBB.threads 多个直接静态代码注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Groupee UBB.threads 6.5.1.1中的多个直接静态代码注入漏洞,远程攻击者可以通过(1)通过theme[]数组参数将PHP代码注入admin/doedittheme.php中,随后再注入includes/theme.inc.php中;(2)通过config[]数组参数将PHP代码注入admin/doeditconfig.php,然后通过includes/config.inc.php执行该代码;以及通过config[path]参数中的URL将引用注入PHP代码,然后通过(3) dorat
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2006-5137

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2006-5137

登录查看更多情报信息。

Same Patch Batch · n/a · 2006-10-02 · 58 CVEs total

CVE-2006-5122Mercury SiteScope 多个跨站脚本攻击漏洞
CVE-2006-5134Mercury SiteScope 新监视描述拒绝服务漏洞
CVE-2006-5138Groupee UBB.threads 'subscriptions.php' 敏感信息泄露漏洞
CVE-2006-5136Groupee UBB.threads 'ubbt.inc.php' 多个PHP远程文件包含漏洞
CVE-2006-5135A-Blog 多个PHP远程文件包含漏洞
CVE-2006-5139MkPortal Urlobox未明漏洞
CVE-2006-5126John Himmelman PowerPortal 'Index.PHP'远程文件包含漏洞
CVE-2006-5125phpMyWebmin 'home.php'目录遍历漏洞
CVE-2006-5124Joshua Muheim phpMyWebmin 多个PHP远程文件包含漏洞
CVE-2006-5123PHProjekt lib_path及lang_path变量多个远程文件包含漏洞
CVE-2006-5127Bartels Schoene ConPresso 多个跨站脚本攻击漏洞
CVE-2006-5121PostNuke 'Admin.PHP' SQL注入漏洞
CVE-2006-5120Scott Metoyer Red Mombin 多个跨站脚本攻击漏洞
CVE-2006-5119Zen Cart多个跨站脚本攻击漏洞
CVE-2006-5118PHPSelect Web Development 'Index.PHP3'远程文件注入漏洞
CVE-2006-5117PHPMyAdmin Web文档跟目录敏感信息泄露漏洞
CVE-2006-5116PHPMyAdmin多个跨站脚本攻击漏洞
CVE-2006-5115KGB 'Kgcall.php'目录遍历漏洞
CVE-2006-5114SAP Internet Transaction Server多个跨站脚本攻击(XSS)漏洞
CVE-2006-5113已注销:Exporia 'Common.PHP'目录遍历漏洞

Showing top 20 of 58 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2006-5137

No comments yet


Leave a comment