CVE-2006-4191
Summary
| CVE | CVE-2006-4191 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-08-17 01:04:00 UTC |
| Updated | 2021-04-29 15:15:00 UTC |
| Description | Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Xmb Software | Extreme Message Board | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| XMB Langfilenew Local File Include Vulnerability | BID | www.securityfocus.com | |
| Error 404 :( | MISC | retrogod.altervista.org | Exploit |
| Extreme Media Board MemCP.PHP Local File Include Vulnerability | BID | www.securityfocus.com | Exploit |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| XMB 1.9.6 Final - 'basename()' Remote Command Execution - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | |
| SecurityReason - XMB <= 1.9.6 Final basename()/'langfilenew' arbitrary local inclusion / remote commands execution | SREASON | securityreason.com | |
| XMB "u2uid" SQL Injection and Local File Inclusion - Advisories - Secunia | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| Security Issue History - XMBdocs | MISC | docs.xmbforum2.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| XMB | 2021-04-23 | Robert Chapin | XMB versions 1.9.8 and later were checked and are not vulnerable. Upgrades are available at https://www.xmbforum2.com/ |
There are currently no legacy QID mappings associated with this CVE.