Vulnerability CVE-2006-5095


Published: 2006-09-29   Modified: 2012-02-12

Description:
** DISPUTED ** PHP remote file inclusion vulnerability in index.php in MyPhotos 0.1.3b beta allows remote attackers to execute arbitrary PHP code via the includesdir parameter. NOTE: this issue is disputed by CVE on 20060927, since the includesdir is defined before being used when the product is installed according to the provided instructions.

See advisories in our WLB2 database:
Topic
Author
Date
High
MyPhotos<= Remote File Include Vulnerability
Root3r_H3ll
03.10.2006

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Myphotos -> Myphotos 

 References:
http://attrition.org/pipermail/vim/2006-September/001057.html
http://securityreason.com/securityalert/1656
http://www.securityfocus.com/archive/1/446876/100/0/threaded
http://www.securityfocus.com/bid/20160

Copyright 2024, cxsecurity.com

 

Back to Top