CVE Database
/

CVE-2006-4889

Back to search

CVE-2006-4889

Published: Sep 19, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.

VendorProductVersions

n/a

n/a

affected
n/a

References

32201
vdb-entry
x_refsource_OSVDB
32218
vdb-entry
x_refsource_OSVDB
32205
vdb-entry
x_refsource_OSVDB
32217
vdb-entry
x_refsource_OSVDB
32211
vdb-entry
x_refsource_OSVDB
signkorn-log-file-include(28888)
vdb-entry
x_refsource_XF
32214
vdb-entry
x_refsource_OSVDB
32206
vdb-entry
x_refsource_OSVDB
32215
vdb-entry
x_refsource_OSVDB
32200
vdb-entry
x_refsource_OSVDB
32204
vdb-entry
x_refsource_OSVDB
32208
vdb-entry
x_refsource_OSVDB
32203
vdb-entry
x_refsource_OSVDB
32207
vdb-entry
x_refsource_OSVDB
32199
vdb-entry
x_refsource_OSVDB
32202
vdb-entry
x_refsource_OSVDB
32210
vdb-entry
x_refsource_OSVDB
32212
vdb-entry
x_refsource_OSVDB
19977
vdb-entry
x_refsource_BID
32213
vdb-entry
x_refsource_OSVDB
32209
vdb-entry
x_refsource_OSVDB
1619
third-party-advisory
x_refsource_SREASON
32216
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now