CVE-2006-2964 Information
Feb 14, 2021
cve
Description
Multiple PHP remote file inclusion vulnerabilities in Xtreme Scripts Download Manager (aka Xtreme Downloads) 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) download.php (2) manager.php (3) admin/scripts/category.php (4) includes/add_allow.php (5) admin/index.php and (6) admin/admin/login.php.
Reference
http://securityreason.com/securityalert/1072 http://www.osvdb.org/26643 http://www.osvdb.org/26644 http://www.osvdb.org/26645 http://www.osvdb.org/26646 http://www.osvdb.org/26647 http://www.osvdb.org/26648 http://www.securityfocus.com/archive/1/436104/100/0/threaded http://www.securityfocus.com/archive/1/436107/100/0/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/26961
Share on: