10
CVSSv2

CVE-2006-7052

Published: 24/02/2007 Updated: 29/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote malicious users to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.php, (b) showcatpicks.php, and (c) showarticle.php; and the (2) admin_header_file and (3) admin_footer_file parameters to (d) admin/authors.php, (e) admin/index.php, (f) admin/categories.php, (g) admin/editconfig.php, and (h) admin/articles.php.

Vulnerable Product Search on Vulmon Subscribe to Product

keith reichley dotwidget for articles 0.2

Exploits

source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute i ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execu ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in t ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and exe ...
source: wwwsecurityfocuscom/bid/18479/info dotWidget for Articles is prone to multiple remote file-include vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it ...