10
CVSSv2

CVE-2006-7173

Published: 20/03/2007 Updated: 19/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and previous versions allows remote malicious users to execute arbitrary PHP code via a crafted option_new[report_w_day] parameter in a preferenze action, which can be later accessed via option/php-stats-options.php.

Vulnerable Product Search on Vulmon Subscribe to Product

php-stats php-stats

Exploits

<?php print_r(' --------------------------------------------------------------------------- Php-Stats <= 0191b admin 2 exec() exploit by rgod mail: retrog at alice dot it site: retrogodaltervistaorg dork example: inurl:php-statsjsphp --------------------------------------------------------------------------- '); /* to be used ...