9.3
CVSSv2

CVE-2006-6869

Published: 31/12/2006 Updated: 19/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and previous versions, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote malicious users to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

maxdev mdforum

Exploits

<? //Kacper & str0ke Settings $exploit_name = "MDForum <= 201 (PNSVlang) Remote Code Execution Exploit"; $script_name = "MDForum 201"; $script_site = "wwwmaxdevpl/Contents,Download,View,8phtml"; $dork = '"Powered by MDForum"'; //************************************************************** print ' ::::::::: :::::::::: ...