CVE Database
/

CVE-2006-3771

Back to search

CVE-2006-3771

Published: Jul 21, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) articles.php, (2) contact.php, (3) displaypage.php, (4) faq.php, (5) mainbody.php, (6) news.php, (7) registration.php, (8) whosOnline.php, (9) components/com_calendar.php, (10) components/com_forum.php, (11) components/minibb/index.php, (12) components/minibb/bb_admin.php, (13) components/minibb/bb_plugins.php, (14) modules/mod_calendar.php, (15) modules/mod_browser_prefs.php, (16) modules/mod_counter.php, (17) modules/mod_online.php, (18) modules/mod_stats.php, (19) modules/mod_weather.php, (20) themes/bizz.php, (21) themes/default.php, (22) themes/simple.php, (23) themes/original.php, (24) themes/portal.php, (25) themes/purple.php, and other unspecified files.

VendorProductVersions

n/a

n/a

affected
n/a

References

28652
vdb-entry
x_refsource_OSVDB
28665
vdb-entry
x_refsource_OSVDB
28661
vdb-entry
x_refsource_OSVDB
28654
vdb-entry
x_refsource_OSVDB
28670
vdb-entry
x_refsource_OSVDB
28653
vdb-entry
x_refsource_OSVDB
19090
vdb-entry
x_refsource_BID
28655
vdb-entry
x_refsource_OSVDB
28663
vdb-entry
x_refsource_OSVDB
28660
vdb-entry
x_refsource_OSVDB
28651
vdb-entry
x_refsource_OSVDB
28648
vdb-entry
x_refsource_OSVDB
28671
vdb-entry
x_refsource_OSVDB
28649
vdb-entry
x_refsource_OSVDB
1016551
vdb-entry
x_refsource_SECTRACK
28669
vdb-entry
x_refsource_OSVDB
28656
vdb-entry
x_refsource_OSVDB
28664
vdb-entry
x_refsource_OSVDB
28647
vdb-entry
x_refsource_OSVDB
28658
vdb-entry
x_refsource_OSVDB
28668
vdb-entry
x_refsource_OSVDB
28662
vdb-entry
x_refsource_OSVDB
1265
third-party-advisory
x_refsource_SREASON
2046
exploit
x_refsource_EXPLOIT-DB
28659
vdb-entry
x_refsource_OSVDB
28650
vdb-entry
x_refsource_OSVDB
28667
vdb-entry
x_refsource_OSVDB
28657
vdb-entry
x_refsource_OSVDB
28666
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now