CVE Database
/

CVE-2006-1767

Back to search

CVE-2006-1767

Published: Apr 13, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in nicecoder.com INDEXU 5.0.0 and 5.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the theme_path parameter in (1) index.php, (2) become_editor.php, (3) add.php, (4) bad_link.php, (5) browse.php, (6) detail.php, (7) fav.php, (8) get_rated.php, (9) login.php, (10) mailing_list.php, (11) new.php, (12) modify.php, (13) pick.php, (14) power_search.php, (15) rating.php, (16) register.php, (17) review.php, (18) rss.php, (19) search.php, (20) send_pwd.php, (21) sendmail.php, (22) tell_friend.php, (23) top_rated.php, (24) user_detail.php, and (25) user_search.php; and the (26) base_path parameter in invoice.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

28415
vdb-entry
x_refsource_OSVDB
28426
vdb-entry
x_refsource_OSVDB
17470
vdb-entry
x_refsource_BID
28406
vdb-entry
x_refsource_OSVDB
28412
vdb-entry
x_refsource_OSVDB
1015891
vdb-entry
x_refsource_SECTRACK
28419
vdb-entry
x_refsource_OSVDB
28410
vdb-entry
x_refsource_OSVDB
28417
vdb-entry
x_refsource_OSVDB
28427
vdb-entry
x_refsource_OSVDB
28422
vdb-entry
x_refsource_OSVDB
24597
vdb-entry
x_refsource_OSVDB
24596
vdb-entry
x_refsource_OSVDB
1016331
vdb-entry
x_refsource_SECTRACK
28416
vdb-entry
x_refsource_OSVDB
28425
vdb-entry
x_refsource_OSVDB
28413
vdb-entry
x_refsource_OSVDB
28409
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now