6.4
CVSSv2

CVE-2006-4962

Published: 23/09/2006 Updated: 19/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 650
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and previous versions allows remote malicious users to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log file.

Vulnerable Product Search on Vulmon Subscribe to Product

blue dragon php blue dragon platinum_2.8.0

blue dragon php blue dragon platinum_2.9.1

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? $devilteam = " ::::::::: :::::::::: ::: ::: ::::::::::: ::: :+: :+: :+: :+: :+: :+: :+: +:+ +:+ +:+ +:+ +:+ +:+ +:+ +#+ +:+ +#++:++# +#+ +:+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ +#+ ...
<?php // Exploit Name: Php Blue Dragon CMS 300 Code Execution Exploit //Script Homepage: phpbluedragonpl/ // Autor: Kacper [kacper1964@yahoopl] // Autor Homepage: devilteameu | kacperbblogpl //Pozdrawiam wszystkich ludzi z DEVIL TEAM, Zapraszam na irc! //Irc: ircmilw0rmcom:6667 #devilteam //Elo if ($argc<7) { print ...