5.1
CVSSv2

CVE-2006-2608

Published: 26/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote malicious users to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as demonstrated by injecting PHP code into info.php.

Vulnerable Product Search on Vulmon Subscribe to Product

artmedic webdesign artmedic newsletter 4.1

Exploits

source: wwwsecurityfocuscom/bid/18047/info Artmedic Newsletter is prone to a remote PHP code-execution vulnerability This issue is due to a failure in the application to properly sanitize user-supplied input An attacker can exploit this issue to create files containing arbitrary content that can include arbitrary malicious PHP code and ...