CVE-2006-5101 (CNNVD-200610-037)

HIGH
中文标题:
Comdev CSV Importer 'include.php'PHP远程文件包含漏洞
英文标题:
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, ...
CVSS分数: 7.5
发布时间: 2006-10-02 20:00:00
漏洞类型: 代码注入
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v3
漏洞描述
中文描述:

Comdev CSV Importer 3.1可能还有4.1的include.php中存在PHP远程文件包含漏洞(用在(1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1和 (12) Comdev eCommerce 3.1中),远程攻击者可以通过path[docroot]参数中的URL执行任意PHP代码。

英文描述:

PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.

CWE类型:
CWE-94
标签:
(暂无数据)
受影响产品
厂商 产品 版本 版本范围 平台 CPE
comdev comdev_csv_importer 3.1 - - cpe:2.3:a:comdev:comdev_csv_importer:3.1:*:*:*:*:*:*:*
comdev comdev_csv_importer 4.1 - - cpe:2.3:a:comdev:comdev_csv_importer:4.1:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
ADV-2006-3807 vdb-entry
cve.org
访问
ADV-2006-3811 vdb-entry
cve.org
访问
29300 vdb-entry
cve.org
访问
29310 vdb-entry
cve.org
访问
20060927 Comdev News Publisher 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
22147 third-party-advisory
cve.org
访问
22157 third-party-advisory
cve.org
访问
20060927 Comdev Contact Form 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
20060927 Comdev eCommerce 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
29303 vdb-entry
cve.org
访问
ADV-2006-3806 vdb-entry
cve.org
访问
22153 third-party-advisory
cve.org
访问
22169 third-party-advisory
cve.org
访问
ADV-2006-3809 vdb-entry
cve.org
访问
ADV-2006-3813 vdb-entry
cve.org
访问
1658 third-party-advisory
cve.org
访问
29305 vdb-entry
cve.org
访问
20060927 Comdev Newsletter 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
29311 vdb-entry
cve.org
访问
22170 third-party-advisory
cve.org
访问
20060927 Comdev Photo Gallery 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
29307 vdb-entry
cve.org
访问
20060927 Comdev Events Calendar 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
22168 third-party-advisory
cve.org
访问
20060927 Comdev Guestbook 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
29304 vdb-entry
cve.org
访问
22149 third-party-advisory
cve.org
访问
ADV-2006-3808 vdb-entry
cve.org
访问
20060927 Comdev Vote Caster 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
ADV-2006-3804 vdb-entry
cve.org
访问
22135 third-party-advisory
cve.org
访问
29306 vdb-entry
cve.org
访问
22154 third-party-advisory
cve.org
访问
22134 third-party-advisory
cve.org
访问
ADV-2006-3812 vdb-entry
cve.org
访问
20060927 Comdev FAQ Support 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
ADV-2006-3810 vdb-entry
cve.org
访问
29308 vdb-entry
cve.org
访问
22133 third-party-advisory
cve.org
访问
29302 vdb-entry
cve.org
访问
20060927 Comdev Customer Helpdesk 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
ADV-2006-3805 vdb-entry
cve.org
访问
comdev-include-file-include(29220) vdb-entry
cve.org
访问
29301 vdb-entry
cve.org
访问
ADV-2006-3803 vdb-entry
cve.org
访问
29299 vdb-entry
cve.org
访问
20060927 Comdev Links Directory 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
20060927 Comdev Web Blogger 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
22151 third-party-advisory
cve.org
访问
ADV-2006-3814 vdb-entry
cve.org
访问
20060927 Comdev CSV Importer 3.1 :) <= Remote File Inclusion mailing-list
cve.org
访问
29309 vdb-entry
cve.org
访问
ADV-2006-3815 vdb-entry
cve.org
访问
CVSS评分详情
7.5
HIGH
CVSS向量: AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS版本: 2.0
机密性
PARTIAL
完整性
PARTIAL
可用性
PARTIAL
时间信息
发布时间:
2006-10-02 20:00:00
修改时间:
2024-08-07 19:41:05
创建时间:
2025-11-11 15:32:37
更新时间:
2025-11-11 15:49:10
利用信息
暂无可利用代码信息
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2006-5101 2025-11-11 15:17:45 2025-11-11 07:32:37
NVD nvd_CVE-2006-5101 2025-11-11 14:51:51 2025-11-11 07:41:23
CNNVD cnnvd_CNNVD-200610-037 2025-11-11 15:08:53 2025-11-11 07:49:10
版本与语言
当前版本: v3
主要语言: EN
支持语言:
EN ZH
安全公告
暂无安全公告信息
变更历史
v3 CNNVD
2025-11-11 15:49:10
vulnerability_type: 未提取 → 代码注入; cnnvd_id: 未提取 → CNNVD-200610-037; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 代码注入
  • cnnvd_id: 未提取 -> CNNVD-200610-037
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:41:23
severity: SeverityLevel.MEDIUM → SeverityLevel.HIGH; cvss_score: 未提取 → 7.5; cvss_vector: NOT_EXTRACTED → AV:N/AC:L/Au:N/C:P/I:P/A:P; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 2; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
  • cvss_score: 未提取 -> 7.5
  • cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:P/I:P/A:P
  • cvss_version: NOT_EXTRACTED -> 2.0
  • affected_products_count: 0 -> 2
  • data_sources: ['cve'] -> ['cve', 'nvd']