CVE-2006-0786 Information
Description
Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier with allow_url_fopen enabled allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL which bypasses the check for \http://\ \ftp://\ and \https://\ URLs.
Reference
http://retrogod.altervista.org/phpkit_161r2_incl_xpl.html
http://securityreason.com/securityalert/445
http://securitytracker.com/id?1015640
http://www.securityfocus.com/archive/1/425196/100/0/threaded
Incomplete
blacklist
vulnerability
in
include.php
in
PHPKIT
1.6.1
Release
2
and
earlier
with
allow_url_fopen
enabled
allows
remote
attackers
to
conduct
PHP
remote
file
include
attacks
via
a
path
parameter
that
specifies
a
(1)
UNC
share
or
(2)
ftps
URL
which
bypasses
the
check
for
[*http://*](http://)
\ftp://
and
[*https://*](https://)
URLs.