7.5
CVSSv2

CVE-2006-5234

Published: 11/10/2006 Updated: 14/05/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote malicious users to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable

Vulnerable Product Search on Vulmon Subscribe to Product

phpwebsite phpwebsite 0.10.2

Exploits

source: wwwsecurityfocuscom/bid/20412/info phpWebSite is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data Exploiting these issues could allow an attacker to compromise the application and the underlying system; other attacks are also possible phpWebSite version 0102 i ...