CVE Database
/

CVE-2006-3136

Back to search

CVE-2006-3136

Published: Jun 22, 2006

Modified: Jan 17, 2025

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and to files in path/nucleus including (2) media.php, (3) /xmlrpc/server.php, and (4) /xmlrpc/api_metaweblog.inc.php. NOTE: this is a similar vulnerability to CVE-2006-2583. NOTE: this issue has been disputed by third parties, who state that the DIR_LIBS parameter is defined in an include file before being used

VendorProductVersions

n/a

n/a

affected
n/a

References

27502
vdb-entry
x_refsource_OSVDB
1120
third-party-advisory
x_refsource_SREASON
ADV-2006-2408
vdb-entry
x_refsource_VUPEN
1016325
vdb-entry
x_refsource_SECTRACK
20060616 file include exploits in nucleus 3.23
mailing-list
x_refsource_BUGTRAQ
18475
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now