[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2006-5101Date: (C)2006-10-03   (M)2023-12-22


PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 7.5
Exploit Score: 10.0
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SREASON-1658
http://www.securityfocus.com/archive/1/archive/1/447184/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447192/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447188/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447213/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447201/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447207/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447185/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447190/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447209/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447187/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447186/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447193/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/447194/100/0/threaded
SECUNIA-22133
SECUNIA-22134
SECUNIA-22135
SECUNIA-22147
SECUNIA-22149
SECUNIA-22151
SECUNIA-22153
SECUNIA-22154
SECUNIA-22157
SECUNIA-22168
SECUNIA-22169
SECUNIA-22170
OSVDB-29299
OSVDB-29300
OSVDB-29301
OSVDB-29302
OSVDB-29303
OSVDB-29304
OSVDB-29305
OSVDB-29306
OSVDB-29307
OSVDB-29308
OSVDB-29309
OSVDB-29310
OSVDB-29311
ADV-2006-3803
ADV-2006-3804
ADV-2006-3805
ADV-2006-3806
ADV-2006-3807
ADV-2006-3808
ADV-2006-3809
ADV-2006-3810
ADV-2006-3811
ADV-2006-3812
ADV-2006-3813
ADV-2006-3814
ADV-2006-3815
comdev-include-file-include(29220)

CWE    1
CWE-94

© SecPod Technologies