CVE-2006-2686
Summary
| CVE | CVE-2006-2686 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-05-31 10:06:00 UTC |
| Updated | 2017-10-19 01:29:00 UTC |
| Description | PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Actionapps | Actionapps | 2.8.1 | All | All | All |
| Application | Actionapps | Actionapps | 2.8.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 27262 | OSVDB | www.osvdb.org | |
| 27297 | OSVDB | www.osvdb.org | |
| 27271 | OSVDB | www.osvdb.org | |
| 27284 | OSVDB | www.osvdb.org | |
| 27290 | OSVDB | www.osvdb.org | |
| 27265 | OSVDB | www.osvdb.org | |
| 27283 | OSVDB | www.osvdb.org | |
| 27257 | OSVDB | www.osvdb.org | |
| 27276 | OSVDB | www.osvdb.org | |
| 27303 | OSVDB | www.osvdb.org | |
| 27310 | OSVDB | www.osvdb.org | |
| 27299 | OSVDB | www.osvdb.org | |
| 27278 | OSVDB | www.osvdb.org | |
| 27259 | OSVDB | www.osvdb.org | |
| ActionApps Multiple Remote File Include Vulnerabilities | BID | www.securityfocus.com | |
| 27304 | OSVDB | www.osvdb.org | |
| ActionApps "GLOBALS[AA_INC_PATH]" File Inclusion - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| 27301 | OSVDB | www.osvdb.org | |
| 27288 | OSVDB | www.osvdb.org | |
| APC ActionApps CMS 2.8.1 Remote File Include Vulnerabilities | EXPLOIT-DB | www.exploit-db.com | |
| 27306 | OSVDB | www.osvdb.org | |
| 27269 | OSVDB | www.osvdb.org | |
| 27260 | OSVDB | www.osvdb.org | |
| 27295 | OSVDB | www.osvdb.org | |
| 27273 | OSVDB | www.osvdb.org | |
| 27286 | OSVDB | www.osvdb.org | |
| 27292 | OSVDB | www.osvdb.org | |
| 27267 | OSVDB | www.osvdb.org | |
| 27308 | OSVDB | www.osvdb.org | |
| 27281 | OSVDB | www.osvdb.org | |
| 27274 | OSVDB | www.osvdb.org | |
| 27279 | OSVDB | www.osvdb.org | |
| 27258 | OSVDB | www.osvdb.org | |
| 27305 | OSVDB | www.osvdb.org | |
| 27302 | OSVDB | www.osvdb.org | |
| 27298 | OSVDB | www.osvdb.org | |
| 27291 | OSVDB | www.osvdb.org | |
| 27264 | OSVDB | www.osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 27282 | OSVDB | www.osvdb.org | |
| 27256 | OSVDB | www.osvdb.org | |
| 27277 | OSVDB | www.osvdb.org | |
| 27263 | OSVDB | www.osvdb.org | |
| 27296 | OSVDB | www.osvdb.org | |
| 27270 | OSVDB | www.osvdb.org | |
| 27285 | OSVDB | www.osvdb.org | |
| 27293 | OSVDB | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| 27266 | OSVDB | www.osvdb.org | |
| 27280 | OSVDB | www.osvdb.org | |
| 27309 | OSVDB | www.osvdb.org | |
| 27275 | OSVDB | www.osvdb.org | |
| 27254 | OSVDB | www.osvdb.org | |
| 27261 | OSVDB | www.osvdb.org | |
| 27294 | OSVDB | www.osvdb.org | |
| 27253 | OSVDB | www.osvdb.org | |
| 27272 | OSVDB | www.osvdb.org | |
| 27287 | OSVDB | www.osvdb.org | |
| 27268 | OSVDB | www.osvdb.org | |
| 27289 | OSVDB | www.osvdb.org | |
| 27300 | OSVDB | www.osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.