CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2006-3361

MEDIUM
5.1
CVSS Severity Score
EPSS Score0.1680%
EPSS Percentile4.28th
Published2006年7月6日
Last Modified2026年4月16日

Vulnerability Description

PHP remote file inclusion vulnerability in Stud.IP 1.3.0-2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) _PHPLIB[libdir] parameter in studip-phplib/oohforms.inc and (2) ABSOLUTE_PATH_STUDIP parameter in studip-htdocs/archiv_assi.php.

Affected Platforms (CPE)

📦
Stud.ip

Stud.ip

<= 1.3.0-2

References & Advisories

相關漏洞威脅