Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-4287
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-4287

Description:
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/28486

SAID
  Secunia Advisory: SA21593

OSVDB
  28048
  28047
  28046
  28044
  28045
  28049
  28050
  28051
  28052
  28053
  28054

MISC
  http://www.rahim.webd.pl/exploity/Exploits/61.html
  http://milw0rm.com/exploits/2226

BID
  19611


Return to the previous page.