7.5
CVSSv2

CVE-2006-3475

Published: 10/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in free QBoard 1.1 allow remote malicious users to execute arbitrary PHP code via a URL in the qb_path parameter to (1) index.php, (2) about.php, (3) contact.php, (4) delete.php, (5) faq.php, (6) features.php or (7) history.php, a different set of vectors than CVE-2006-2998.

Vulnerable Product Search on Vulmon Subscribe to Product

free qboard free qboard 1.1

Exploits

source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webse ...
source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the w ...
source: wwwsecurityfocuscom/bid/18788/info The free QBoard script is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process ...
source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the web ...
source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserv ...
source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver ...
source: wwwsecurityfocuscom/bid/18780/info Plume CMS is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver p ...