CVE-2006-0147
Summary
| CVE | CVE-2006-0147 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-01-09 23:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | John Lim | Adodb | 4.66 | All | All | All |
| Application | John Lim | Adodb | 4.68 | All | All | All |
| Application | Mantis | Mantis | 0.19.4 | All | All | All |
| Application | Mantis | Mantis | 1.0.0_rc4 | All | All | All |
| Application | Moodle | Moodle | 1.5.3 | All | All | All |
| Application | Postnuke Software Foundation | Postnuke | 0.761 | All | All | All |
| Application | The Cacti Group | Cacti | 0.8.6g | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PHPOpenChat ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| PostNuke ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| www.osvdb.org/22291 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Cacti ADOdb "server.php" Insecure Test Script Security Issue - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1030-1 moodle | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| Debian -- Security Information -- DSA-1029-1 libphp-adodb | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Secunia - Advisories - Gentoo update for cacti | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for libphp-adodb - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Gentoo Linux Documentation -- Cacti: Multiple vulnerabilities in included ADOdb | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | Patch, Vendor Advisory |
| Simplog Multiple Vulnerabilities and Security Issues - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Error 404 :( | af854a3a-2127-422b-91ae-364da2661108 | retrogod.altervista.org | Exploit |
| Vulnerability and Virus Information - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Patch, Vendor Advisory |
| Secunia - Advisories - Moodle ADOdb Insecure Test Scripts Security Issues | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Debian -- Security Information -- DSA-1031-1 cacti | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Error 404 :( | af854a3a-2127-422b-91ae-364da2661108 | retrogod.altervista.org | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian update for moodle - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Simplog <= 0.9.2 (s) Remote Commands Execution Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Xaraya ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| ADOdb Insecure Test Scripts Security Issues - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Patch, Vendor Advisory |
| Secunia - Advisories - Mantis ADOdb Insecure Test Scripts Security Issues | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian update for cacti - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.