CVE Database
/

CVE-2006-0755

Back to search

CVE-2006-0755

Published: Feb 18, 2006

Modified: Jan 16, 2025

PUBLISHED

Description

Multiple PHP remote file include vulnerabilities in dotProject 2.0.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary commands via the baseDir parameter in (1) db_adodb.php, (2) db_connect.php, (3) session.php, (4) vw_usr_roles.php, (5) calendar.php, (6) date_format.php, and (7) tasks/gantt.php; and the dPconfig[root_dir] parameter in (8) projects/gantt.php, (9) gantt2.php, and (10) vw_files.php. NOTE: the vendor disputes this issue, stating that the product documentation clearly recommends that the system administrator disable register_globals, and that the check.php script warns against this setting. Also, the vendor says that the protection.php/siteurl vector is incorrect because protection.php does not exist in the product

VendorProductVersions

n/a

n/a

affected
n/a

References

23210
vdb-entry
x_refsource_OSVDB
23216
vdb-entry
x_refsource_OSVDB
23217
vdb-entry
x_refsource_OSVDB
18879
third-party-advisory
x_refsource_SECUNIA
23209
vdb-entry
x_refsource_OSVDB
16648
vdb-entry
x_refsource_BID
23212
vdb-entry
x_refsource_OSVDB
23215
vdb-entry
x_refsource_OSVDB
23213
vdb-entry
x_refsource_OSVDB
ADV-2006-0604
vdb-entry
x_refsource_VUPEN
23214
vdb-entry
x_refsource_OSVDB
23218
vdb-entry
x_refsource_OSVDB
23211
vdb-entry
x_refsource_OSVDB
23219
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now