7.5
CVSSv2

CVE-2006-4311

Published: 23/08/2006 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in Sonium Enterprise Adressbook 0.2 allows remote malicious users to execute arbitrary PHP code via the folder parameter in multiple files in the plugins directory, as demonstrated by plugins/1_Adressbuch/delete.php.

Vulnerable Product Search on Vulmon Subscribe to Product

sonium enterprise adressbook 0.2

Exploits

+-------------------------------------------------------------------- + + Sonium Enterprise Adressbook Version 02 (folder) RFI + + Original advisory: + wwwbb-pcsecurityde/Websecurity/342/org/Sonium_Enterprise_Adressbook_Version_02_(folder)_RFIhtm + +-------------------------------------------------------------------- + + Affected Softwa ...