CVE Database
/

CVE-2006-3850

Back to search

CVE-2006-3850

Published: Jul 25, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected

VendorProductVersions

n/a

n/a

affected
n/a

References

20060724 Vanilla CMS
mailing-list
x_refsource_VIM
20060725 Vanilla CMS
mailing-list
x_refsource_VIM
1016568
vdb-entry
x_refsource_SECTRACK
19127
vdb-entry
x_refsource_BID
28287
vdb-entry
x_refsource_OSVDB
1281
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now