Описание
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-2877
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26933
- http://secunia.com/advisories/19758
- http://securityreason.com/securityalert/1058
- http://securitytracker.com/id?1016224
- http://www.osvdb.org/26599
- http://www.osvdb.org/26600
- http://www.osvdb.org/26601
- http://www.osvdb.org/26602
- http://www.securityfocus.com/archive/1/435964/100/0/threaded
- http://www.securityfocus.com/archive/1/436027/100/0/threaded
- http://www.securityfocus.com/bid/18281
EPSS
CVE ID
Связанные уязвимости
PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.
EPSS