CVE Database
/

CVE-2006-1747

Back to search

CVE-2006-1747

Published: Apr 12, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.php, (2) war.php, (3) stats.php, (4) news.php, (5) joinus.php, (6) challenge.php, (7) calendar.php, (8) member.php, (9) popup.php, and other unspecified scripts in the admin folder. NOTE: these are different attack vectors than CVE-2006-1636 and CVE-2006-1503.

VendorProductVersions

n/a

n/a

affected
n/a

References

17443
vdb-entry
x_refsource_BID
1658
exploit
x_refsource_EXPLOIT-DB
19387
vdb-entry
x_refsource_BID
20060408 Virtual War File İnclusion
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now