Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-5101
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-5101

Description:
PHP remote file inclusion vulnerability in include.php in Comdev CSV Importer 3.1 and possibly 4.1, as used in (1) Comdev Contact Form 3.1, (2) Comdev Customer Helpdesk 3.1, (3) Comdev Events Calendar 3.1, (4) Comdev FAQ Support 3.1, (5) Comdev Guestbook 3.1, (6) Comdev Links Directory 3.1, (7) Comdev News Publisher 3.1, (8) Comdev Newsletter 3.1, (9) Comdev Photo Gallery 3.1, (10) Comdev Vote Caster 3.1, (11) Comdev Web Blogger 3.1, and (12) Comdev eCommerce 3.1, allows remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter. NOTE: it has been reported that 4.1 versions might also be affected.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/29220

SREASON
  http://securityreason.com/securityalert/1658

SAID
  Secunia Advisory: SA22153
  Secunia Advisory: SA22151
  Secunia Advisory: SA22149
  Secunia Advisory: SA22147
  Secunia Advisory: SA22134
  Secunia Advisory: SA22133
  Secunia Advisory: SA22135
  Secunia Advisory: SA22154
  Secunia Advisory: SA22157
  Secunia Advisory: SA22168
  Secunia Advisory: SA22169
  Secunia Advisory: SA22170

OSVDB
  29309
  29308
  29304
  29311
  29306
  29307
  29310
  29303
  29305
  29301
  29302
  29299
  29300

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/447194/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447186/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447193/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447209/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447187/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447190/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447185/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447201/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447207/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447213/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447188/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447192/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/447184/100/0/threaded


Return to the previous page.