CVE-2006-4004
Summary
| CVE | CVE-2006-4004 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-07 19:04:00 UTC |
| Updated | 2017-10-19 01:29:00 UTC |
| Description | Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vbportal | Vbportal | 3.0.2 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_beta_2 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_beta_3 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_gold | All | All | All |
| Application | Vbportal | Vbportal | 3.6.0_beta_1 | All | All | All |
| Application | Vbportal | Vbportal | 3.0.2 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_beta_2 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_beta_3 | All | All | All |
| Application | Vbportal | Vbportal | 3.5.0_gold | All | All | All |
| Application | Vbportal | Vbportal | 3.6.0_beta_1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| vbPortal "bbvbplang" Local File Inclusion Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| VBPortal BBVBPLang Parameter Local File inclusion Vulnerability | BID | www.securityfocus.com | Exploit |
| Discuss Security audit [Important] - phpPortals Community Forums | MISC | www.phpportals.com | |
| vbPortal 3.0.2 <= 3.6.0 b1 (cookie) Remote Code Excution Exploit | EXPLOIT-DB | www.exploit-db.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.