Sploitus

CVE-2006-0147

1 known exploit for CVE-2006-0147

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.

John Lim Adodb
= 4.66, 4.68
Mantis
= 0.19.4, 1.0.0_rc4
Moodle
= 1.5.3
Postnuke Software Foundation Postnuke
= 0.761
The Cacti Group Cacti
= 0.8.6g
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
13.1% (96th percentile)
NVD status
Modified
Published
2006-01-09
CVE-2006-0147 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-0147

Proof-of-concept code and exploit modules indexed by Sploitus