« Volver al listado

CVE-2006-6966

Estado: ModificadaAlta (7.5)—💥 Exploit

phpGraphy anterior 0.9.13a no desasigna adecuadamente las variables cuando los datos de enteada incluyen un parámetro numérico con un valor de validación: un valor de hash de parámetro alfanumérico, el cual permite a atacantes remotos ejecutar código PHP de su eleccióna través de la actualización del fichero config.php a través del parámetro pictures[] en index.php. NOTA: podría argumentarse que esta vulnerabilidad es debido a un bug el comando PHP unset (CVE-2006-3017) y la propia solución estaría en el PHP; por lo tanto, no debería tratarse como una vulnerabilidad en phpGraphy.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

💥 Exploits públicos

Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-6966",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-02-04T00:28:00.000",
  "references": [
    {
      "url": "http://phpgraphy.sourceforge.net/changelog.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://retrogod.altervista.org/phpgraphy_0912_zhdkoi_cmd.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1017571",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/forum/forum.php?forum_id=659277",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30634",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://phpgraphy.sourceforge.net/changelog.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://retrogod.altervista.org/phpgraphy_0912_zhdkoi_cmd.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1017571",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/forum/forum.php?forum_id=659277",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30634",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "phpGraphy before 0.9.13a does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary PHP code by uploading a config.php file via the pictures[] parameter to index.php.  NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in phpGraphy."
    },
    {
      "lang": "es",
      "value": "phpGraphy anterior 0.9.13a no desasigna adecuadamente las variables cuando los datos de enteada incluyen un parámetro numérico con un valor de validación: un valor de hash de parámetro alfanumérico, el cual permite a atacantes remotos ejecutar código PHP de su eleccióna través de la actualización del fichero config.php a través del parámetro pictures[] en index.php. NOTA: podría argumentarse que esta vulnerabilidad es debido a un bug el comando PHP unset (CVE-2006-3017) y  la propia solución estaría en el PHP; por lo tanto, no debería tratarse como una vulnerabilidad en phpGraphy."
    }
  ],
  "lastModified": "2026-06-16T22:34:08.247",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F037DBB9-3299-4354-B678-2181DA1BBA17",
              "versionEndIncluding": "0.9.13"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B76498A5-3928-465F-8368-1388EA328FC4"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E01F56B-9EAC-418A-9995-022BD521267D"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB306E0B-97A8-4E0C-85F5-909E4749BF5C"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2DB2C7A-F3C4-4DC0-BFAE-9F0BABB69DF9"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AF1E410-19D3-468E-9B3D-4ACB13CEE84B"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7EA030F-D70A-4175-83DE-075ADA7B7577"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D767774C-9529-4199-9164-2D66F6B9A4E8"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9DBAFCE-F705-4954-97AE-4620B2B8FE77"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "474A1D36-894E-4A6B-BF5B-37B28A03489A"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07054102-C5F8-440F-9123-F1098BE5C972"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.9a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F83775BB-7D82-4E5F-9501-EF405F246BDC"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63F46B5E-2D7A-46FB-87FE-CB866341C9B1"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.10a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "559C1B1F-B145-4571-AFE5-2B3BF1C9D5EB"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63A085EA-ED9C-483B-9B0B-51EFEB1585CC"
            },
            {
              "criteria": "cpe:2.3:a:phpgraphy:phpgraphy:0.9.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A9A25C9-DF34-4C73-83C5-674BF704E554"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}