Vulnerabilities > CVE-2005-1681 - Unspecified vulnerability in Bugada Andrea PHP Advanced Transfer Manager 1.20/1.21
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | PHP Advanced Transfer Manager 1.21 Arbitrary File Include Vulnerability. CVE-2005-1681. Webapps exploit for php platform |
id | EDB-ID:25686 |
last seen | 2016-02-03 |
modified | 2005-05-19 |
published | 2005-05-19 |
reporter | Ingvar Gilbert |
source | https://www.exploit-db.com/download/25686/ |
title | PHP Advanced Transfer Manager 1.21 - Arbitrary File Include Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | PHPATM_ARBITRARY_UPLOADS.NASL |
description | The version of PHP Advanced Transfer Manager installed on the remote host allows authenticated users to upload arbitrary files and then run them subject to the privileges of the web server user. It also allows unauthenticated users to read arbitrary files on the remote host and possibly even run arbitrary PHP code, subject to the privileges of the web server user. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18207 |
published | 2005-05-09 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18207 |
title | PHP Advanced Transfer Manager <= 1.21 Multiple Vulnerabilities |
code |
|
References
- http://marc.info/?l=bugtraq&m=111653168810937&w=2
- http://marc.info/?l=bugtraq&m=111653168810937&w=2
- http://secunia.com/advisories/15420
- http://secunia.com/advisories/15420
- http://securitytracker.com/id?1014008
- http://securitytracker.com/id?1014008
- http://www.osvdb.org/16692
- http://www.osvdb.org/16692