5.1
CVSSv2

CVE-2006-2745

Published: 01/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and previous versions, when register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao.

Vulnerable Product Search on Vulmon Subscribe to Product

facile interactive web facile interactive web 0.8.41

facile interactive web facile interactive web

Exploits

F@cile Interactive Web <= 08x Multiple Remote Vulnerabilities Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedxcom web: wwwnukedxcom This exploits works on F@cile Interactive Web <= 08x Original advisory can be found at: wwwnukedxcom/?viewdoc=35 File Inclusion Vulnerabilities [victim]/[FacilePath]/p-popupgalleryphp?l=ht ...