7.5
CVSSv2

CVE-2006-2645

Published: 30/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in manager/frontinc/prepend.php for Plume 1.0.3 allows remote malicious users to execute arbitrary code via a URL in the _PX_config[manager_path] parameter. NOTE: this is a different executable and affected version than CVE-2006-0725.

Vulnerable Product Search on Vulmon Subscribe to Product

plume-cms plume cms 1.0.3

Exploits

Vendor: Plume CMS plume-cmsnet Vuln: Remote File Include Discovered: beford <xbefordx gmail com> Vulnerable File/Code /plume-103/manager/frontinc/prependphp [code] include_once $_PX_config['manager_path']'/conf/configphp'; [/code] urlandaorg/manager/frontinc/prependphp?_PX_config[manager_path]=leet # milw0rm ...