CVE-2006-3847 Information
Feb 14, 2021
cve
Description
PHP remote file inclusion vulnerability in (1) admin.php and possibly (2) details.php (3) modify.php (4) newgroup.php (5) newtask.php and (6) rss.php in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter.
Reference
http://kurdishsecurity.blogspot.com/2006/07/kurdish-security-14-mospray-basedir.html http://secunia.com/advisories/21166 http://www.securityfocus.com/archive/1/440939/100/200/threaded http://www.securityfocus.com/bid/19122 http://www.vupen.com/english/advisories/2006/2932 https://exchange.xforce.ibmcloud.com/vulnerabilities/27917 https://www.exploit-db.com/exploits/2062
Share on: