CVE Database
/

CVE-2006-3175

Back to search

CVE-2006-3175

Published: Jun 23, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.

VendorProductVersions

n/a

n/a

affected
n/a

References

27460
vdb-entry
x_refsource_OSVDB
18476
vdb-entry
x_refsource_BID
27461
vdb-entry
x_refsource_OSVDB
1125
third-party-advisory
x_refsource_SREASON
27462
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now