CVE Database
/

CVE-2006-6740

Back to search

CVE-2006-6740

Published: Dec 26, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5) admin_newcomm.inc.php, (6) header_admin.inc.php, (7) header.inc.php, (8) friends.inc.php, (9) menu_u.inc.php, (10) notify.inc.php, (11) body.inc.php, (12) body_admin.inc.php, (13) commrecc.inc.php, (14) do_reg.inc.php, (15) comm_post.inc.php, or (16) menu_v.inc.php in include/, different vectors than CVE-2006-5634. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

32375
vdb-entry
x_refsource_OSVDB
32363
vdb-entry
x_refsource_OSVDB
32372
vdb-entry
x_refsource_OSVDB
32374
vdb-entry
x_refsource_OSVDB
ADV-2006-5087
vdb-entry
x_refsource_VUPEN
32376
vdb-entry
x_refsource_OSVDB
32365
vdb-entry
x_refsource_OSVDB
32370
vdb-entry
x_refsource_OSVDB
32366
vdb-entry
x_refsource_OSVDB
32368
vdb-entry
x_refsource_OSVDB
23423
third-party-advisory
x_refsource_SECUNIA
32369
vdb-entry
x_refsource_OSVDB
32364
vdb-entry
x_refsource_OSVDB
32371
vdb-entry
x_refsource_OSVDB
20070301 phpProfiles vendor ack
mailing-list
x_refsource_VIM
32367
vdb-entry
x_refsource_OSVDB
21667
vdb-entry
x_refsource_BID
32373
vdb-entry
x_refsource_OSVDB
2956
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now