CVE-2006-3172
Summary
| CVE | CVE-2006-3172 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-23 00:02:00 UTC |
| Updated | 2017-07-20 01:32:00 UTC |
| Description | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b) cms/plugins/poll/poll.inc.php, (c) cms/plugins/user_managment/usrPortrait.inc.php, (d) cms/plugins/user_managment/user.inc.php, (e) cms/plugins/media_manager/media.inc.php, (f) cms/plugins/events/permanent.eventMonth.inc.php, (g) cms/plugins/events/events.inc.php, and (h) cms/plugins/newsletter2/newsletter.inc.php; (2) path[cb] parameter to (i) modules/guestbook/guestbook.inc.php, (j) modules/shoutbox/shoutBox.php, and (k) modules/sitemap/sitemap.inc.php; and the (3) rel parameter to (l) modules/download/overview.inc.php, (m) modules/download/detailView.inc.php, (n) modules/article/fullarticle.inc.php, (o) modules/article/comments.inc.php, (p) modules/article2/overview.inc.php, (q) modules/article2/fullarticle.inc.php, (r) modules/article2/comments.inc.php, (s) modules/headline/headlineBox.php, and (t) modules/headline/showHeadline.inc.php. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Content*builder | Content*builder | 0.7.5 | All | All | All |
| Application | Content*builder | Content*builder | 0.7.5 | All | All | All |
| Application | Content*builder | Content*builder | 0.7.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 26358 | OSVDB | www.osvdb.org | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 26345 | OSVDB | www.osvdb.org | Exploit |
| 26356 | OSVDB | www.osvdb.org | Exploit |
| 26363 | OSVDB | www.osvdb.org | Exploit |
| 26351 | OSVDB | www.osvdb.org | Exploit |
| 26347 | OSVDB | www.osvdb.org | Exploit |
| 26354 | OSVDB | www.osvdb.org | Exploit |
| 26361 | OSVDB | www.osvdb.org | Exploit |
| 26353 | OSVDB | www.osvdb.org | Exploit |
| 26349 | OSVDB | www.osvdb.org | Exploit |
| 'Content-Builder (CMS) 0.7.5, Remote command execution' - MARC | BUGTRAQ | marc.info | |
| 26362 | OSVDB | www.osvdb.org | Exploit |
| 26350 | OSVDB | www.osvdb.org | Exploit |
| 26344 | OSVDB | www.osvdb.org | Exploit |
| Content*Builder File Inclusion Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| 26357 | OSVDB | www.osvdb.org | Exploit |
| 26359 | OSVDB | www.osvdb.org | Exploit |
| Content-Builder Multiple Remote File Include Vulnerabilities | BID | www.securityfocus.com | Exploit |
| 26348 | OSVDB | www.osvdb.org | Exploit |
| 26360 | OSVDB | www.osvdb.org | Exploit |
| 26352 | OSVDB | www.osvdb.org | Exploit |
| 26346 | OSVDB | www.osvdb.org | Exploit |
| 26355 | OSVDB | www.osvdb.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.