7.5
CVSSv2

CVE-2006-5899

Published: 15/11/2006 Updated: 11/04/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in install.php3 in @cid stats 2.3 allows remote malicious users to execute arbitrary PHP code via a URL in the repertoire parameter. NOTE: this issue has been disputed by a third party, who states that install.php3 is supposed to be deleted after installation and, if not deleted, intentionally allows setting repertoire without an inclusion attack

Vulnerable Product Search on Vulmon Subscribe to Product

acid stats acid stats 2.3

Exploits

source: wwwsecurityfocuscom/bid/20925/info The '@cid stats' program is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible Version 23 is vulnerable ...