Vulnerabilities > CVE-2005-1222 - Remote Security vulnerability in Netref 4.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
netref
nessus

Summary

cat_for_gen.php in Annuaire Netref 4.2 allows remote attackers to execute arbitrary PHP code by setting the ad_direct parameter to reference cat_for_gen.php, then including the code in the m_for_racine parameter, which is then written to cat_for_gen.php.

Vulnerable Configurations

Part Description Count
Application
Netref
1

Nessus

NASL familyCGI abuses
NASL idNETREF_CAT_FOR_GEN.NASL
descriptionThe remote host is running the Netref directory script, written in PHP. There is a vulnerability in the installed version of Netref that enables a remote attacker to pass arbitrary PHP script code through the
last seen2020-06-01
modified2020-06-02
plugin id18358
published2005-05-23
reporterCopyright (C) 2005-2018 Josh Zlatin-Amishav
sourcehttps://www.tenable.com/plugins/nessus/18358
titleNetref cat_for_gen.php Arbitrary PHP Command Injection