CVE-2006-5506 Information
Description
Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php (2) inc/lib/boxes.lib.php (3) inc/lib/tools.lib.php (4) tools/trackback/index.php and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php (7) lib/boxes.lib.php and (8) lib/history.lib.php in inc/.
Reference
http://secunia.com/advisories/22547 http://wiclear.free.fr/ http://wiclear.free.fr/?Download http://www.osvdb.org/29942 http://www.osvdb.org/29943 http://www.osvdb.org/29944 http://www.osvdb.org/29945 http://www.osvdb.org/29946 http://www.osvdb.org/29947 http://www.osvdb.org/29948 http://www.osvdb.org/29949 http://www.vupen.com/english/advisories/2006/4166 https://exchange.xforce.ibmcloud.com/vulnerabilities/29720 https://www.exploit-db.com/exploits/2624
Share on: