Vulnerabilities > CVE-2005-2157 - Remote Security vulnerability in Nabocorp Nabopoll 1.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
nabocorp
nessus
exploit available

Summary

PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

Vulnerable Configurations

Part Description Count
Application
Nabocorp
1

Exploit-Db

descriptionnabopoll 1.2 (survey.inc.php path) Remote File Include Vulnerability. CVE-2005-2157. Webapps exploit for php platform
idEDB-ID:3315
last seen2016-01-31
modified2007-02-15
published2007-02-15
reporterCr@zy_King
sourcehttps://www.exploit-db.com/download/3315/
titlenabopoll 1.2 survey.inc.php path Remote File Include Vulnerability

Nessus

NASL familyCGI abuses
NASL idNABOPOLL_PATH_REMOTE_INCLUDES.NASL
descriptionThe remote host is running nabopoll, a web-based voting / survey software for PHP and MySQL. The installed version of nabopoll allows remote attackers to control the
last seen2020-06-01
modified2020-06-02
plugin id18618
published2005-07-05
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/18618
titleNabopoll survey.inc.php path Parameter Remote File Inclusion