HIGH · 7.5

CVE-2006-0147

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, ...

Vulnerability Description

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
John LimAdodb4.66
MantisMantis0.19.4
MoodleMoodle1.5.3
Postnuke Software FoundationPostnuke0.761
The Cacti GroupCacti0.8.6g

References

FAQ

What is CVE-2006-0147?

CVE-2006-0147 is a vulnerability with a CVSS score of 7.5 (HIGH). Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, ...

How severe is CVE-2006-0147?

CVE-2006-0147 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0147?

Check the references section above for vendor advisories and patch information. Affected products include: John Lim Adodb, Mantis Mantis, Moodle Moodle, Postnuke Software Foundation Postnuke, The Cacti Group Cacti.