Extreme Media Board MemCP.PHP Local File Include Vulnerability
BID:19501
CVE-2006-4191 |Info
Extreme Media Board MemCP.PHP Local File Include Vulnerability
| Bugtraq ID: | 19501 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4191 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 14 2006 12:00AM |
| Updated: | Sep 11 2008 03:10PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
XMB Forum 1.9.6 XMB Extreme MEssage Board 1.9.6 |
| Not Vulnerable: |
XMB Forum 1.9.8 |
Discussion
Extreme Media Board MemCP.PHP Local File Include Vulnerability
Extreme Media Board is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to execute arbitrary local scripts within the context of the affected application.
Extreme Media Board 1.96 and prior versions are vulnerable to this issue; other versions may also be affected.
Extreme Media Board is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
A successful exploit may allow an attacker to execute arbitrary local scripts within the context of the affected application.
Extreme Media Board 1.96 and prior versions are vulnerable to this issue; other versions may also be affected.
Exploit / POC
Extreme Media Board MemCP.PHP Local File Include Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Extreme Media Board MemCP.PHP Local File Include Vulnerability
Solution:
A vendor update is available. Contact the vendor for more information.
Solution:
A vendor update is available. Contact the vendor for more information.
References
Extreme Media Board MemCP.PHP Local File Include Vulnerability
References:
References:
- Summary of Official Vendor Statements (XMB)
- Xtreme Message Board Home Page (Adventure Media)