CVE-2006-2158
Last modified
CVE-2006-2158 is a vulnerability of currently unknown severity. Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.
Description
Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion using the include_files array parameter.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Stadtaus | Guestbook Script | <= 1.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2158?
How severe is CVE-2006-2158?
How do I fix CVE-2006-2158?
Are you affected by CVE-2006-2158?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
