5
CVSSv2

CVE-2006-0687

Published: 15/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows remote malicious users to include arbitrary local files or possibly remote files via a modified includeModule and siteModInfo variable.

Vulnerable Product Search on Vulmon Subscribe to Product

docmgr docmgr 0.54.2

Exploits

<?php # ---docmgr_0542_incl_xplphp 030 12/02/2006 # # # # DocMGR <= 0542 remote commands execution exploit # # coded by rgod # # ...