Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-2005

Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.124
EPSS Ranking 93.6%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-2005


Contact Us

Shodan ® - All rights reserved