CVE Database
/

CVE-2006-4990

Back to search

CVE-2006-4990

Published: Sep 26, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-admlog.php, (3) adm-approve.php, (4) adm-backup.php, (5) adm-cats.php, (6) adm-cinc.php, (7) adm-db.php, (8) adm-editcfg.php, (9) adm-inc.php, (10) adm-index.php, (11) adm-modcom.php, (12) adm-move.php, (13) adm-options.php, (14) adm-order.php, (15) adm-pa.php, (16) adm-photo.php, (17) adm-purge.php, (18) adm-style.php, (19) adm-templ.php, (20) adm-userg.php, (21) adm-users.php, (22) bulkupload.php, (23) cookies.php, (24) comments.php, (25) ecard.php, (26) editphoto.php, (27) register.php, (28) showgallery.php, (29) showmembers.php, (30) useralbums.php, (31) uploadphoto.php, (32) search.php, or (33) adm-menu.php, different vectors than CVE-2006-4828.

VendorProductVersions

n/a

n/a

affected
n/a

References

32240
vdb-entry
x_refsource_OSVDB
32253
vdb-entry
x_refsource_OSVDB
32233
vdb-entry
x_refsource_OSVDB
32247
vdb-entry
x_refsource_OSVDB
32230
vdb-entry
x_refsource_OSVDB
32252
vdb-entry
x_refsource_OSVDB
32245
vdb-entry
x_refsource_OSVDB
32223
vdb-entry
x_refsource_OSVDB
32250
vdb-entry
x_refsource_OSVDB
32227
vdb-entry
x_refsource_OSVDB
32237
vdb-entry
x_refsource_OSVDB
32222
vdb-entry
x_refsource_OSVDB
32248
vdb-entry
x_refsource_OSVDB
32231
vdb-entry
x_refsource_OSVDB
32246
vdb-entry
x_refsource_OSVDB
32228
vdb-entry
x_refsource_OSVDB
32221
vdb-entry
x_refsource_OSVDB
32232
vdb-entry
x_refsource_OSVDB
32234
vdb-entry
x_refsource_OSVDB
32249
vdb-entry
x_refsource_OSVDB
1632
third-party-advisory
x_refsource_SREASON
32239
vdb-entry
x_refsource_OSVDB
32235
vdb-entry
x_refsource_OSVDB
32229
vdb-entry
x_refsource_OSVDB
32226
vdb-entry
x_refsource_OSVDB
32236
vdb-entry
x_refsource_OSVDB
32243
vdb-entry
x_refsource_OSVDB
32224
vdb-entry
x_refsource_OSVDB
32251
vdb-entry
x_refsource_OSVDB
32238
vdb-entry
x_refsource_OSVDB
32225
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now