4
CVSSv2

CVE-2006-4418

Published: 28/08/2006 Updated: 19/10/2017
CVSS v2 Base Score: 4 | Impact Score: 4.9 | Exploitability Score: 4.9
VMScore: 405
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote malicious users to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.

Vulnerable Product Search on Vulmon Subscribe to Product

wikepage wikepage 2006.2

wikepage wikepage 2006.2a

Exploits

#!/usr/bin/perl # # WIKEPAGE <= V20062a Opus 10 Remote Command Execution Exploit # ------------------------------------------------------------- # IHST: h4ckerzcom / hackerzir # AST : Aria-SecurityNet # Kapda : kapdair # #### (c)oded & discovered By Hessam-x ( Hessamx -at- Hessamxnet) use IO::Socket; use LWP::Simple; print "--------- ...