CVE-2006-4532

Properties

Published:
31.08.2006
Updated:
20.10.2017
Patch available:
Severity:
High
CVSS vector:
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Product:
bernard_pacques: yet_another_community_system_cms

Vulnerability description

PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter.

References:

SECTRACK: http://securitytracker.com/id?1016775
VUPEN: http://www.vupen.com/english/advisories/2006/3425
CONFIRM: http://www.yetanothercommunitysystem.com/yacs/articles/view.php/1664
XF: https://exchange.xforce.ibmcloud.com/vulnerabilities/28682
EXPLOIT-DB: https://www.exploit-db.com/exploits/2282