7.5
CVSSv2

CVE-2006-4733

Published: 13/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.

Vulnerable Product Search on Vulmon Subscribe to Product

sips sips

sips sips 0.3.0pl1

sips sips 0.3.0pl2

sips sips 0.2.2

sips sips 0.2.4

sips sips 0.3.0

Exploits

******************************************************************************* # Title : SIPS <= 031(boxincphp) Remote File Include Vulnerability # Author : ajann # Contact : :( # SPage : sourceforgenet/projects/sips/ # $$ : Free ******************************************************************************* [[ERROR] ...