CVE-2006-4677 Information

Description

LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks DISPUTED LICENSE README.md cvefilelist cvelist nvdcve nvdpages.sh scripts test-CVE-2017-1882.markdown test-CVE-2017-18822.markdown tmpvendorlinks PHP remote file inclusion vulnerability in contrib/yabbse/poc.php in phpopenchat before 3.0.2 allows remote attackers to execute arbitrary PHP code via the sourcedir parameter. NOTE: this issue was disputed by a third-party researcher who stated that the _REQUEST parameters were dynamically unset at the beginning of the file. Another researcher noted and CVE agrees that the unset PHP function can be bypassed (CVE-2006-3017). If this issue is due to a vulnerability in PHP then it should be excluded from CVE.

Reference

http://phpopenchat.org/index.php http://www.securityfocus.com/archive/1/445384/100/0/threaded http://www.securityfocus.com/archive/1/445522/100/0/threaded http://www.securityfocus.com/archive/1/445580/100/0/threaded

Share on: