Vulnerability Details CVE-2006-4788
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.067
EPSS Ranking 90.8%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2006-4788
-
cpe:2.3:a:telekorn:signkorn_guestbook:*
-
cpe:2.3:a:telekorn:signkorn_guestbook:1.1
-
cpe:2.3:a:telekorn:signkorn_guestbook:1.2