9.3
CVSSv2

CVE-2006-7185

Published: 30/03/2007 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote malicious users to execute arbitrary PHP code via a URL in the relative_root parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cmsmelborp cmsmelborp beta

Exploits

#!/usr/bin/perl ## # Portal Name : CMSmelborp(user_standardphp) Remote File Inclusion Exploit # Bug Found DeltahackingSecurityTEAM Code :DrTrojan&DrPantagon ## # Download =superb-westdlsourceforgenet/sourceforge/cmsmelborp/CMSmelborpzip # ## # usage: # perl CMSmelborppl <target> <cmd shell location> <cmd shell vari ...