CVE Database
/

CVE-2006-5020

Back to search

CVE-2006-5020

Published: Sep 27, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) DomainsPage.class.php, (25) EditAccountPage.class.php, (26) EditDomainPage.class.php, (27) EditDomainServicePage.class.php, (28) EditHostingServicePage.class.php, (29) EditPaymentPage.class.php, (30) EditProductPage.class.php, (31) EditServerPage.class.php, (32) EmailInvoicePage.class.php, (33) ExecuteOrderPage.class.php, (34) ExpiredDomainsPage.class.php, (35) FulfilledOrdersPage.class.php, (36) GenerateInvoicesPage.class.php, (37) HomePage.class.php, (38) InactiveAccountsPage.class.php, (39) IPManagerPage.class.php, (40) LoginPage.class.php, (41) LogPage.class.php, (42) ModulesPage.class.php, (43) NewAccountPage.class.php, (44) NewDomainServicePage.class.php, (45) NewProductPage.class.php, (46) OutstandingInvoicesPage.class.php, (47) PendingAccountsPage.class.php, (48) PendingOrdersPage.class.php, (49) PrintInvoicePage.class.php, (50) ProductsPage.class.php, (51) RegisterDomainPage.class.php, (52) RegisteredDomainsPage.class.php, (53) ServersPage.class.php, (54) ServicesHostingServicesPage.class.php, (55) ServicesNewHostingPage.class.php, (56) ServicesPage.class.php, (57) ServicesWebHostingPage.class.php, (58) SettingsPage.class.php, (59) TaxesPage.class.php, (60) TransferDomainPage.class.php, (61) ViewAccountPage.class.php, (62) ViewDomainServicePage.class.php, (63) ViewHostingServicePage.class.php, (64) ViewInvoicePage.class.php, (65) ViewLogMessagePage.class.php, (66) ViewOrderPage.class.php, (67) ViewProductPage.class.php, (68) ViewServerPage.class.php, (69) WelcomeEmailPage.class.php; and (70) modules/RegistrarModule.class.php, (71) modules/SolidStateModule.class.php, (72) modules/authorizeaim/authorizeaim.class.php, and (73) modules/authorizeaim/pages/AAIMConfigPage.class.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

31120
vdb-entry
x_refsource_OSVDB
31147
vdb-entry
x_refsource_OSVDB
31141
vdb-entry
x_refsource_OSVDB
31139
vdb-entry
x_refsource_OSVDB
31192
vdb-entry
x_refsource_OSVDB
31106
vdb-entry
x_refsource_OSVDB
31135
vdb-entry
x_refsource_OSVDB
31117
vdb-entry
x_refsource_OSVDB
20070106 vendor ack: SolidState RFI
mailing-list
x_refsource_VIM
31144
vdb-entry
x_refsource_OSVDB
21934
vdb-entry
x_refsource_BID
31100
vdb-entry
x_refsource_OSVDB
31112
vdb-entry
x_refsource_OSVDB
31109
vdb-entry
x_refsource_OSVDB
31193
vdb-entry
x_refsource_OSVDB
31115
vdb-entry
x_refsource_OSVDB
31131
vdb-entry
x_refsource_OSVDB
31203
vdb-entry
x_refsource_OSVDB
31194
vdb-entry
x_refsource_OSVDB
31146
vdb-entry
x_refsource_OSVDB
31191
vdb-entry
x_refsource_OSVDB
31105
vdb-entry
x_refsource_OSVDB
31119
vdb-entry
x_refsource_OSVDB
31197
vdb-entry
x_refsource_OSVDB
31136
vdb-entry
x_refsource_OSVDB
31116
vdb-entry
x_refsource_OSVDB
31099
vdb-entry
x_refsource_OSVDB
31114
vdb-entry
x_refsource_OSVDB
31134
vdb-entry
x_refsource_OSVDB
31190
vdb-entry
x_refsource_OSVDB
31145
vdb-entry
x_refsource_OSVDB
31122
vdb-entry
x_refsource_OSVDB
31111
vdb-entry
x_refsource_OSVDB
31104
vdb-entry
x_refsource_OSVDB
31113
vdb-entry
x_refsource_OSVDB
31199
vdb-entry
x_refsource_OSVDB
31128
vdb-entry
x_refsource_OSVDB
2413
exploit
x_refsource_EXPLOIT-DB
31125
vdb-entry
x_refsource_OSVDB
31107
vdb-entry
x_refsource_OSVDB
31098
vdb-entry
x_refsource_OSVDB
31137
vdb-entry
x_refsource_OSVDB
31200
vdb-entry
x_refsource_OSVDB
31143
vdb-entry
x_refsource_OSVDB
31198
vdb-entry
x_refsource_OSVDB
31123
vdb-entry
x_refsource_OSVDB
31126
vdb-entry
x_refsource_OSVDB
31124
vdb-entry
x_refsource_OSVDB
31201
vdb-entry
x_refsource_OSVDB
31097
vdb-entry
x_refsource_OSVDB
31110
vdb-entry
x_refsource_OSVDB
31121
vdb-entry
x_refsource_OSVDB
31133
vdb-entry
x_refsource_OSVDB
31138
vdb-entry
x_refsource_OSVDB
31130
vdb-entry
x_refsource_OSVDB
31127
vdb-entry
x_refsource_OSVDB
31202
vdb-entry
x_refsource_OSVDB
31108
vdb-entry
x_refsource_OSVDB
31129
vdb-entry
x_refsource_OSVDB
31132
vdb-entry
x_refsource_OSVDB
31118
vdb-entry
x_refsource_OSVDB
31142
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2006-5020 - Security Vulnerability | QwikSec