CVE Database
/

CVE-2006-5220

Back to search

CVE-2006-5220

Published: Oct 9, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a) WYApplication.php, (b) WYDocument.php, (c) WYEditor.php, (d) WYElement.php, (e) WYFile.php, (f) WYHTMLTag.php, (g) WYImage.php, (h) WYLanguage.php, (i) WYLink.php, (j) WYPath.php, (k) WYPopupWindowLink.php, (l) WYSelectMenu.php, and (m) WYTextArea.php; (2) files in the programm/elements/ directory including (n) WYGalleryElement.php, (o) WYGuestbookElement.php, (p) WYImageElement.php, (q) WYLogonButtonElement.php, (r) WYLongTextElement.php, (s) WYLoopElement.php, (t) WYMenuElement.php, and (u) WYShortTextElement.php; and (3) programm/webyep.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

1702
third-party-advisory
x_refsource_SREASON
2496
exploit
x_refsource_EXPLOIT-DB
29654
vdb-entry
x_refsource_OSVDB
29648
vdb-entry
x_refsource_OSVDB
29660
vdb-entry
x_refsource_OSVDB
29645
vdb-entry
x_refsource_OSVDB
20406
vdb-entry
x_refsource_BID
29644
vdb-entry
x_refsource_OSVDB
29649
vdb-entry
x_refsource_OSVDB
29656
vdb-entry
x_refsource_OSVDB
29659
vdb-entry
x_refsource_OSVDB
ADV-2006-3972
vdb-entry
x_refsource_VUPEN
29652
vdb-entry
x_refsource_OSVDB
29650
vdb-entry
x_refsource_OSVDB
webyep-webyep-file-include(29397)
vdb-entry
x_refsource_XF
22336
third-party-advisory
x_refsource_SECUNIA
29658
vdb-entry
x_refsource_OSVDB
1017023
vdb-entry
x_refsource_SECTRACK
29653
vdb-entry
x_refsource_OSVDB
29657
vdb-entry
x_refsource_OSVDB
29662
vdb-entry
x_refsource_OSVDB
29663
vdb-entry
x_refsource_OSVDB
29661
vdb-entry
x_refsource_OSVDB
29647
vdb-entry
x_refsource_OSVDB
29646
vdb-entry
x_refsource_OSVDB
29643
vdb-entry
x_refsource_OSVDB
29651
vdb-entry
x_refsource_OSVDB
29655
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now