Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-6171

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.04
EPSS Ranking 87.9%
CVSS Severity
CVSS v2 Score 9.3
References
Products affected by CVE-2008-6171
  • Drupal » Drupal » Version: 5.0
    cpe:2.3:a:drupal:drupal:5.0
  • Drupal » Drupal » Version: 5.1
    cpe:2.3:a:drupal:drupal:5.1
  • Drupal » Drupal » Version: 5.10
    cpe:2.3:a:drupal:drupal:5.10
  • Drupal » Drupal » Version: 5.11
    cpe:2.3:a:drupal:drupal:5.11
  • Drupal » Drupal » Version: 5.2
    cpe:2.3:a:drupal:drupal:5.2
  • Drupal » Drupal » Version: 5.3
    cpe:2.3:a:drupal:drupal:5.3
  • Drupal » Drupal » Version: 5.4
    cpe:2.3:a:drupal:drupal:5.4
  • Drupal » Drupal » Version: 5.5
    cpe:2.3:a:drupal:drupal:5.5
  • Drupal » Drupal » Version: 5.6
    cpe:2.3:a:drupal:drupal:5.6
  • Drupal » Drupal » Version: 5.7
    cpe:2.3:a:drupal:drupal:5.7
  • Drupal » Drupal » Version: 5.8
    cpe:2.3:a:drupal:drupal:5.8
  • Drupal » Drupal » Version: 5.9
    cpe:2.3:a:drupal:drupal:5.9
  • Drupal » Drupal » Version: 6.0
    cpe:2.3:a:drupal:drupal:6.0
  • Drupal » Drupal » Version: 6.1
    cpe:2.3:a:drupal:drupal:6.1
  • Drupal » Drupal » Version: 6.2
    cpe:2.3:a:drupal:drupal:6.2
  • Drupal » Drupal » Version: 6.3
    cpe:2.3:a:drupal:drupal:6.3
  • Drupal » Drupal » Version: 6.4
    cpe:2.3:a:drupal:drupal:6.4
  • Drupal » Drupal » Version: 6.5
    cpe:2.3:a:drupal:drupal:6.5


Contact Us

Shodan ® - All rights reserved