Secunia Logo
 
CVE Reference: CVE-2006-1478
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1478

Description:
Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by uploading PHP code in a gl_session cookie to users.php, which causes the code to be stored in error.log, which is then included by initiate.php.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25489

SREASON
  http://securityreason.com/securityalert/641

SAID
  Secunia Advisory: SA19428

MISC
  http://www.worlddefacers.de/Public/WD-TMPLH.txt
  http://www.turnkeywebtools.com/forum/showthread.php?p=10415

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/428976/100/0/threaded


Return to the previous page.