CVE-2006-4271 Information

Description

LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks PHP remote file inclusion vulnerability in install/upgrade_301.php in Jelsoft vBulletin 3.5.4 allows remote attackers to execute arbitrary PHP code via a URL in the step parameter. NOTE: the vendor has disputed this vulnerability saying \The default vBulletin requires authentication prior to the usage of the upgrade system.\

Reference

http://archives.neohapsis.com/archives/bugtraq/2006-07/0061.html http://archives.neohapsis.com/archives/bugtraq/2006-07/0069.html http://archives.neohapsis.com/archives/bugtraq/2006-07/0121.html http://archives.neohapsis.com/archives/bugtraq/2006-07/0217.html http://www.osvdb.org/28210 http://www.pldsoft.com/forum/showthread.php?t=1340

Share on: