Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2006-4863
StatusCandidate
Description** DISPUTED **  Multiple PHP remote file inclusion vulnerabilities in Marc Cagninacci mcLinksCounter 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the langfile parameter in (1) login.php, (2) stats.php, (3) detail.php, or (4) erase.php.  NOTE: CVE and a third party dispute this vulnerability, because the langfile parameter is set to english.php in each file.
SeverityHigh
CVSS score7
CVSS vector(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
PhaseAssigned (19.09.2006)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4863
ReferencesBUGTRAQ : 20060914 mcLinksCounter v1.1 - Remote File Include Vulnerabilities
 BUGTRAQ : 20060918 Re: mcLinksCounter v1.1 - Remote File Include Vulnerabilities
SecurityVulns:Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server