CVE-2006-3193
Summary
| CVE | CVE-2006-3193 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-06-23 00:02:00 UTC |
| Updated | 2017-10-19 01:29:00 UTC |
| Description | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2) addbioform.php, (3) addfliersform.php, (4) addgenmerchform.php, (5) addinterviewsform.php, (6) addlinksform.php, (7) addlyricsform.php, (8) addmembioform.php, (9) addmerchform.php, (10) addmerchpicform.php, (11) addnewsform.php, (12) addphotosform.php, (13) addreleaseform.php, (14) addreleasepicform.php, (15) addrelmerchform.php, (16) addreviewsform.php, (17) addshowsform.php, (18) addwearmerchform.php; (19) adminpanel/includes/mailinglist/disphtmltbl.php, and (20) adminpanel/includes/mailinglist/dispxls.php. |
Risk And Classification
Problem Types: CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Grayscale | Bandsite Cms | 1.1.1 | All | All | All |
| Application | Grayscale | Bandsite Cms | 1.1.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 27243 | OSVDB | www.osvdb.org | Exploit |
| 27250 | OSVDB | www.osvdb.org | Exploit |
| 27233 | OSVDB | www.osvdb.org | |
| BandSite Root_Path Remote File Include Vulnerability | BID | www.securityfocus.com | |
| 27244 | OSVDB | www.osvdb.org | Exploit |
| 27234 | OSVDB | www.osvdb.org | |
| BandSite CMS "root_path" File Inclusion Vulnerabilities - Advisories - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 27238 | OSVDB | www.osvdb.org | |
| 27248 | OSVDB | www.osvdb.org | Exploit |
| 27241 | OSVDB | www.osvdb.org | Exploit |
| 27252 | OSVDB | www.osvdb.org | Exploit |
| 27246 | OSVDB | www.osvdb.org | |
| Page not found - SourceForge.net | CONFIRM | sourceforge.net | |
| 27236 | OSVDB | www.osvdb.org | |
| Webmail- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| 27245 | OSVDB | www.osvdb.org | Exploit |
| 27235 | OSVDB | www.osvdb.org | |
| 27242 | OSVDB | www.osvdb.org | Exploit |
| 27251 | OSVDB | www.osvdb.org | Exploit |
| 27247 | OSVDB | www.osvdb.org | Exploit |
| 27237 | OSVDB | www.osvdb.org | |
| 27240 | OSVDB | www.osvdb.org | Exploit |
| 27239 | OSVDB | www.osvdb.org | |
| 27249 | OSVDB | www.osvdb.org | Exploit |
| BandSite CMS <= 1.1.1 (root_path) Remote File Include Vulnerabilities | EXPLOIT-DB | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.