6.8
CVSSv2

CVE-2006-0725

Published: 16/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in prepend.php in Plume CMS 1.0.2, when register_globals is enabled, allows remote malicious users to include arbitrary files via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-2645.

Vulnerable Product Search on Vulmon Subscribe to Product

plume-cms plume cms 1.0.2

Exploits

Vendor: Plume CMS plume-cmsnet Vuln: Remote File Include Discovered: beford <xbefordx gmail com> Vulnerable File/Code /plume-103/manager/frontinc/prependphp [code] include_once $_PX_config['manager_path']'/conf/configphp'; [/code] urlandaorg/manager/frontinc/prependphp?_PX_config[manager_path]=leet # milw0rm ...