7.5
CVSSv2

CVE-2006-6575

Published: 15/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and 0.6.1 allows remote malicious users to execute arbitrary PHP code via a URL in the LOGIN_style parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

brian drawert yaplap 0.6.1

brian drawert yaplap 0.6

Exploits

#!/usr/bin/perl #yaplap Remote File Inclusion Vulnerablity #Version 06 & 061 #Class = Remote File Inclusion #Bug Found & Exploit [c]oded By DeltahackingTEAM (DrTrojan&DrPantagon) #Download:osdndlsourceforgenet/sourceforge/yaplap/yaplap-061targz #Vulnerable Code:include $LOGIN_style"_formphp"; #[Path]/Indexphp ...