7.5
CVSSv2

CVE-2006-7068

Published: 02/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.

Vulnerable Product Search on Vulmon Subscribe to Product

cliserv web community 0.61

cliserv web community 0.65

cliserv web community 0.60

cliserv web community 0.50

Exploits

/* +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + - - - [DEVIL TEAM THE BEST POLISH TEAM] - - + +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + - CliServ Web Community <= 065 (cl_headers) Remote File Include Vulnerability + +~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + - [Script name: CliServ Web Community v 065 - [Script sit ...