5
CVSSv2

CVE-2006-5832

Published: 10/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 515
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

All In One Control Panel (AIOCP) 1.3.007 and previous versions allows remote malicious users to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.

Vulnerable Product Search on Vulmon Subscribe to Product

aiocp aiocp 1.3.006

aiocp aiocp 1.3.007

aiocp aiocp 1.3.002

aiocp aiocp 1.3.000

aiocp aiocp 1.3.001

aiocp aiocp 1.3.003

aiocp aiocp 1.3.004

aiocp aiocp 1.3.005

Exploits

source: wwwsecurityfocuscom/bid/20931/info All In One Control Panel (AIOCP) is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied input data Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, access ...
source: wwwsecurityfocuscom/bid/20931/info All In One Control Panel (AIOCP) is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied input data Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, access or ...
source: wwwsecurityfocuscom/bid/20931/info All In One Control Panel (AIOCP) is prone to multiple input-validation vulnerabilities because it fails to sufficiently sanitize user-supplied input data Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, access or modify sensitive ...