7.5
CVSSv2

CVE-2006-1839

Published: 19/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote malicious users to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.

Vulnerable Product Search on Vulmon Subscribe to Product

php album php album 0.3.2.3

Exploits

source: wwwsecurityfocuscom/bid/17526/info phpAlbum is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process This may facilitate unauthorized acce ...