10
CVSSv2

CVE-2006-7132

Published: 06/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote malicious users to include arbitrary local files via the pmdlang parameter to viewticket.php.

Vulnerable Product Search on Vulmon Subscribe to Product

cynux softwares phpmydesk 1.0_beta

Exploits

#!/usr/bin/perl # # PHPMyDesk 10beta Remote Command Execution Exploit # linK : wwwcynuxcom/phpmydesk/ # # (c)od3d and f0unded by Kw3[R]Ln from Romanian Security Team aKA RST-CREWNET # Contact: ciriboflacs[AT]YaHOocom or kw3rln@rst-crewnet # # File inclusion: wwwsitecom/<path>/viewticketphp?pmdlang=<local/remote fil ...