CVE-2006-5165

Properties

Published:
04.10.2006
Updated:
17.10.2006
Patch available:
Severity:
Medium
CVSS vector:
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
Product:
Skrypty: PPA Gallery
Skrypty: PPA Gallery

Vulnerability description

PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[ppa_root_path] parameter.

References:

Milw0rm: http://milw0rm.com/exploits/2446
BID: http://www.securityfocus.com/bid/20255
FRSIRT: http://www.frsirt.com/english/advisories/2006/3842
SECUNIA: http://secunia.com/advisories/22155
XF: http://xforce.iss.net/xforce/xfdb/29231