CVE Database
/

CVE-2006-4533

Back to search

CVE-2006-4533

Published: Sep 1, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in Plume CMS 1.0.6 and earlier allow remote attackers to execute arbitrary PHP code via the _PX_config[manager_path] parameter to (1) articles.php, (2) categories.php, (3) news.php, (4) prefs.php, (5) sites.php, (6) subtypes.php, (7) users.php, (8) xmedia.php, (9) frontinc/class.template.php, (10) inc/lib.text.php, (11) install/index.php, (12) install/upgrade.php, and (13) tools/htaccess/index.php. NOTE: other vectors are covered by CVE-2006-3562, CVE-2006-2645, and CVE-2006-0725.

VendorProductVersions

n/a

n/a

affected
n/a

References

31179
vdb-entry
x_refsource_OSVDB
31172
vdb-entry
x_refsource_OSVDB
31177
vdb-entry
x_refsource_OSVDB
31180
vdb-entry
x_refsource_OSVDB
31171
vdb-entry
x_refsource_OSVDB
31183
vdb-entry
x_refsource_OSVDB
31175
vdb-entry
x_refsource_OSVDB
31181
vdb-entry
x_refsource_OSVDB
19629
vdb-entry
x_refsource_BID
31176
vdb-entry
x_refsource_OSVDB
31178
vdb-entry
x_refsource_OSVDB
31174
vdb-entry
x_refsource_OSVDB
31173
vdb-entry
x_refsource_OSVDB
31182
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now