5.1
CVSSv2

CVE-2006-3317

Published: 29/06/2006 Updated: 07/11/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in phpRaid 3.0.6 allows remote malicious users to execute arbitrary code via a URL in the phpraid_dir parameter to (1) announcements.php and (2) rss.php, a different set of vectors and affected versions than CVE-2006-3316 and CVE-2006-3116.

Vulnerable Product Search on Vulmon Subscribe to Product

spiffyjr phpraid 3.0.6

Exploits

#!/usr/bin/perl # phpraid <= 3xx (rssphp) Remote File Inclusion Exploit # Download Script : up9q9qnet/up/indexphp?f=994a86950 # Founded & Coded by: Cold z3ro , Cold-z3ro@hotmailcom # Dork : inurl:"phpRaid" , "phpRaid" , "rosterphp?Sort=Race" # perl cold-z3ropl <target> <cmd shell location> <cmd shell variable&g ...