CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2006-4277

HIGH
7.5
CVSS Severity Score
EPSS Score0.1030%
EPSS Percentile6.51th
Published2006年8月21日
Last Modified2026年4月16日

Vulnerability Description

Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Affected Platforms (CPE)

📦
Tutti Nova

Tutti Nova

<= 1.6

References & Advisories

相關漏洞威脅