CVE-2006-5165

Properties

Published:
04.10.2006
Updated:
20.10.2017
Patch available:
Severity:
Medium
CVSS vector:
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
Product:
skrypty: ppa_gallery
skrypty: ppa_gallery

Vulnerability description

PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[ppa_root_path] parameter.

References:

BID: http://www.securityfocus.com/bid/20255
VUPEN: http://www.vupen.com/english/advisories/2006/3842
XF: https://exchange.xforce.ibmcloud.com/vulnerabilities/29231
EXPLOIT-DB: https://www.exploit-db.com/exploits/2446