CVE Database
/

CVE-2006-1688

Back to search

CVE-2006-1688

Published: Apr 10, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis. NOTE: this only occurs when register_globals is disabled.

VendorProductVersions

n/a

n/a

affected
n/a

References

24402
vdb-entry
x_refsource_OSVDB
24404
vdb-entry
x_refsource_OSVDB
24411
vdb-entry
x_refsource_OSVDB
ADV-2006-1284
vdb-entry
x_refsource_VUPEN
24403
vdb-entry
x_refsource_OSVDB
24421
vdb-entry
x_refsource_OSVDB
24428
vdb-entry
x_refsource_OSVDB
24407
vdb-entry
x_refsource_OSVDB
24414
vdb-entry
x_refsource_OSVDB
24424
vdb-entry
x_refsource_OSVDB
24425
vdb-entry
x_refsource_OSVDB
24410
vdb-entry
x_refsource_OSVDB
24413
vdb-entry
x_refsource_OSVDB
17434
vdb-entry
x_refsource_BID
24412
vdb-entry
x_refsource_OSVDB
24406
vdb-entry
x_refsource_OSVDB
679
third-party-advisory
x_refsource_SREASON
24409
vdb-entry
x_refsource_OSVDB
19588
third-party-advisory
x_refsource_SECUNIA
24423
vdb-entry
x_refsource_OSVDB
24416
vdb-entry
x_refsource_OSVDB
24408
vdb-entry
x_refsource_OSVDB
24405
vdb-entry
x_refsource_OSVDB
24427
vdb-entry
x_refsource_OSVDB
20060408 Autonomous LAN party File iNclusion
mailing-list
x_refsource_BUGTRAQ
24418
vdb-entry
x_refsource_OSVDB
19482
third-party-advisory
x_refsource_SECUNIA
24426
vdb-entry
x_refsource_OSVDB
24401
vdb-entry
x_refsource_OSVDB
24429
vdb-entry
x_refsource_OSVDB
24422
vdb-entry
x_refsource_OSVDB
24420
vdb-entry
x_refsource_OSVDB
24419
vdb-entry
x_refsource_OSVDB
1015884
vdb-entry
x_refsource_SECTRACK
24417
vdb-entry
x_refsource_OSVDB
24415
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now