CVE-2006-5627 Information

Description

Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php (2) footerhome.php and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php (6) footermain.php (7) headermain.php (8) sitemapfooter.php and (9) sitemapheader.php in templates/.

Reference

http://advisories.echo.or.id/adv/adv53-K-159-2006.txt http://secunia.com/advisories/22623 http://www.osvdb.org/30117 http://www.osvdb.org/30118 http://www.osvdb.org/30119 http://www.osvdb.org/30120 http://www.osvdb.org/30121 http://www.osvdb.org/30122 http://www.osvdb.org/30123 http://www.osvdb.org/30124 http://www.osvdb.org/30125 http://www.securityfocus.com/archive/1/450056/100/0/threaded http://www.securityfocus.com/archive/1/452356/100/0/threaded http://www.securityfocus.com/bid/20801 http://www.vupen.com/english/advisories/2006/4258 https://exchange.xforce.ibmcloud.com/vulnerabilities/29871 https://www.exploit-db.com/exploits/2681

Share on: