5
CVSSv2

CVE-2006-0713

Published: 15/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 520
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in LinPHA 1.0 allows remote malicious users to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the language parameter in (2) install/install.php, (3) install/sec_stage_install.php, (4) install/third_stage_install.php, and (5) install/forth_stage_install.php. NOTE: direct static code injection is resultant from this issue, as demonstrated by inserting PHP code into the username, which is inserted into linpha.log, which is accessible from the directory traversal.

Vulnerable Product Search on Vulmon Subscribe to Product

linpha linpha 0.9.1

linpha linpha 0.9.2

linpha linpha 0.9.3

linpha linpha 0.9.4

linpha linpha 1.0

linpha linpha 0.9.0

Exploits

source: wwwsecurityfocuscom/bid/16592/info LinPHA is prone to multiple local file-inclusion and PHP code-injection vulnerabilities The local file-inclusion issues are due to insecure use of the 'include_once()' PHP function in multiple scripts The PHP code-injection vulnerabilities are due to insufficient input validation of data tha ...
source: wwwsecurityfocuscom/bid/16592/info LinPHA is prone to multiple local file-inclusion and PHP code-injection vulnerabilities The local file-inclusion issues are due to insecure use of the 'include_once()' PHP function in multiple scripts The PHP code-injection vulnerabilities are due to insufficient input validation of data that ...
source: wwwsecurityfocuscom/bid/16592/info LinPHA is prone to multiple local file-inclusion and PHP code-injection vulnerabilities The local file-inclusion issues are due to insecure use of the 'include_once()' PHP function in multiple scripts The PHP code-injection vulnerabilities are due to insufficient input validation of data that ...
source: wwwsecurityfocuscom/bid/16592/info LinPHA is prone to multiple local file-inclusion and PHP code-injection vulnerabilities The local file-inclusion issues are due to insecure use of the 'include_once()' PHP function in multiple scripts The PHP code-injection vulnerabilities are due to insufficient input validation of data that i ...