7.5
CVSSv2

CVE-2006-6041

Published: 22/11/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in Laurent Van den Reysen WORK system e-commerce 3.0.2, and other versions prior to 3.0.4, allow remote malicious users to execute arbitrary PHP code via a URL in the g_include parameter to (1) index.php, (2) module/forum/forum.php, (3) unspecified files under module/, and (4) unspecified files under administration/module/.

Vulnerable Product Search on Vulmon Subscribe to Product

laurent van den reysen work system e-commerce

Exploits

============================================================================================ WORK System E-Commerce (g_include) Remote File Inclusion Vulnerability ============================================================================================ Product: WORK system e-commerce Affected versions: worksystem <= 301 Se ...