5.1
CVSSv2

CVE-2006-5762

Published: 06/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in forgot_pass.php in Free File Hosting 1.1 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: this issue was later reported for the "File Upload System" which is a component of Free File Hosting. This also affects Free Image Hosting 2.0, which contains the same code.

Vulnerable Product Search on Vulmon Subscribe to Product

free php scripts free image hosting 2.0

free php scripts free file hosting

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print ' | \\\\ | \\\ |________ __________\____ _______ ____ |\______ \ \_ _____/\ \ / /| || | | | | \ | __)_ \ Y / | || | | ` \ | \ \ / | || |___ |/_______ //_______ / ...