7.5
CVSSv2

CVE-2005-4211

Published: 14/12/2005 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in coin_includes/db.php in phpCOIN 1.2.2 allows remote malicious users to execute arbitrary PHP code via a URL in the $_CCFG[_PKG_PATH_DBSE] variable.

Vulnerable Product Search on Vulmon Subscribe to Product

coinsoft technologies phpcoin 1.2.2

Exploits

source: wwwsecurityfocuscom/bid/15831/info PhpCOIN is prone to a file include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to include arbitrary remote PHP code and execute it in the context of the Web server process The attacker can also exp ...