« Volver al listado

CVE-2006-4677

Estado: ModificadaAlta (7.5)—

** RECHAZADO ** Vulnerabilidad PHP de inclusión remota de archivo en contrib/yabbse/poc.php en phpopenchat anterior a 3.0.2 permite un atacante remoto ejecutar código PHP de su elección a través del parámetro sourcedir. NOTA: este tema fue discutido por una tercera persona investigador que indicó que eran los parámetros del _REQUEST estaba dinámicamente desactivada al principio del archivo. Otro investigador conocido, y con el que CVE esta de acuerdo, indico que la función PHP desactivada puede evitarse (CVE-2006-3017). Si este tema es debido a una vulnerabilidad en PHP, entonces debe ser excluida del CVE.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-4677",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-09-11T17:04:00.000",
  "references": [
    {
      "url": "http://phpopenchat.org/index.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445384/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445522/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445580/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://phpopenchat.org/index.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445384/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445522/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/445580/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter.  NOTE: this issue was disputed by a third-party researcher who stated that the _REQUEST parameters were dynamically unset at the beginning of the file.  Another researcher noted, and CVE agrees, that the unset PHP function can be bypassed (CVE-2006-3017).  If this issue is due to a vulnerability in PHP, then it should be excluded from CVE"
    },
    {
      "lang": "es",
      "value": "** RECHAZADO ** Vulnerabilidad PHP de inclusión remota de archivo en contrib/yabbse/poc.php en phpopenchat anterior a 3.0.2 permite un atacante remoto ejecutar código PHP de su elección a través del parámetro sourcedir. NOTA: este tema fue discutido por una tercera persona investigador que indicó que eran los parámetros del _REQUEST estaba dinámicamente desactivada al principio del archivo.  Otro investigador conocido, y con el que CVE esta de acuerdo, indico que la función PHP desactivada puede evitarse (CVE-2006-3017).  Si este tema es debido a una vulnerabilidad en PHP, entonces  debe ser excluida del CVE."
    }
  ],
  "lastModified": "2026-06-16T22:29:34.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpopenchat:phpopenchat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37C634AB-40CB-4622-95E9-18BAD8811C2C",
              "versionEndIncluding": "3.0.1"
            },
            {
              "criteria": "cpe:2.3:a:phpopenchat:phpopenchat:2.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89F50264-0D15-4545-ADBC-EA5661353D8E"
            },
            {
              "criteria": "cpe:2.3:a:phpopenchat:phpopenchat:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8893B82A-AA71-45BA-8C50-7D8085C407FD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}