Vulnerability Details CVE-2006-2318
Incomplete blacklist vulnerability in Ideal Science Ideal BB 1.5.4a and earlier allows remote attackers to upload and execute an ASP script via a ".asa" file, which bypasses the check for the ".asp" extension but is executable on the server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.3%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-2318
-
cpe:2.3:a:ideal_science:idealbb:1.4.9
-
cpe:2.3:a:ideal_science:idealbb:1.4.9_beta
-
cpe:2.3:a:ideal_science:idealbb:1.4.9a
-
cpe:2.3:a:ideal_science:idealbb:1.5.0_beta1
-
cpe:2.3:a:ideal_science:idealbb:1.5.0_beta2
-
cpe:2.3:a:ideal_science:idealbb:1.5.0_beta3
-
cpe:2.3:a:ideal_science:idealbb:1.5.0_beta4
-
cpe:2.3:a:ideal_science:idealbb:1.5.0_rc1
-
cpe:2.3:a:ideal_science:idealbb:1.5.1
-
cpe:2.3:a:ideal_science:idealbb:1.5.2
-
cpe:2.3:a:ideal_science:idealbb:1.5.2a
-
cpe:2.3:a:ideal_science:idealbb:1.5.2b
-
cpe:2.3:a:ideal_science:idealbb:1.5.2c
-
cpe:2.3:a:ideal_science:idealbb:1.5.3
-
cpe:2.3:a:ideal_science:idealbb:1.5.3_beta1
-
cpe:2.3:a:ideal_science:idealbb:1.5.3_beta2
-
cpe:2.3:a:ideal_science:idealbb:1.5.3a
-
cpe:2.3:a:ideal_science:idealbb:1.5.3b
-
cpe:2.3:a:ideal_science:idealbb:1.5.4a
-
cpe:2.3:a:ideal_science:idealbb:1.5_beta1
-
cpe:2.3:a:ideal_science:idealbb:1.5_beta2
-
cpe:2.3:a:ideal_science:idealbb:1.5_beta3
-
cpe:2.3:a:ideal_science:idealbb:1.5_beta4
-
cpe:2.3:a:ideal_science:idealbb:1.5_beta5
-
cpe:2.3:a:ideal_science:idealbb:1.5_rc1