[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-1688Date: (C)2006-04-10   (M)2024-02-22


Multiple PHP remote file inclusion vulnerabilities in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allow remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory including (1) ase.php, (2) devi.php, (3) doom3.php, (4) et.php, (5) flashpoint.php, (6) gameSpy.php, (7) gameSpy2.php, (8) gore.php, (9) gsvari.php, (10) halo.php, (11) hlife.php, (12) hlife2.php, (13) igi2.php, (14) main.lib.php, (15) netpanzer.php, (16) old_hlife.php, (17) pkill.php, (18) q2a.php, (19) q3a.php, (20) qworld.php, (21) rene.php, (22) rvbshld.php, (23) savage.php, (24) simracer.php, (25) sof1.php, (26) sof2.php, (27) unreal.php, (28) ut2004.php, and (29) vietcong.php. NOTE: the lib/armygame.php vector is already covered by CVE-2006-1610. The provenance of most of these additional vectors is unknown, although likely from post-disclosure analysis. NOTE: this only occurs when register_globals is disabled.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1015884
BID-17434
SECUNIA-19482
SECUNIA-19588
http://www.securityfocus.com/archive/1/430289/100/0/threaded
http://www.securityfocus.com/archive/1/439874/100/0/threaded
http://www.securityfocus.com/archive/1/441015/100/0/threaded
OSVDB-24401
OSVDB-24402
OSVDB-24403
OSVDB-24404
OSVDB-24405
OSVDB-24406
OSVDB-24407
OSVDB-24408
OSVDB-24409
OSVDB-24410
OSVDB-24411
OSVDB-24412
OSVDB-24413
OSVDB-24414
OSVDB-24415
OSVDB-24416
OSVDB-24417
OSVDB-24418
OSVDB-24419
OSVDB-24420
OSVDB-24421
OSVDB-24422
OSVDB-24423
OSVDB-24424
OSVDB-24425
OSVDB-24426
OSVDB-24427
OSVDB-24428
OSVDB-24429
SREASON-679
ADV-2006-1284
http://liz0zim.no-ip.org/alp.txt
http://www.blogcu.com/Liz0ziM/431845/

CWE    1
CWE-94

© SecPod Technologies