Vulnerabilities > CVE-2005-4593 - Unspecified vulnerability in Joshua Eichorn PHPdocumentor
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in phpDocumentor 1.3.0 rc4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary code via a URL in the (1) FORUM[LIB] parameter in Documentation/tests/bug-559668.php and (2) the root_dir parameter in docbuilder/file_dialog.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Exploit-Db
description | phpDocumentor <= 1.3.0 rc4 Remote Commands Execution Exploit. CVE-2005-4593. Webapps exploit for php platform |
id | EDB-ID:1395 |
last seen | 2016-01-31 |
modified | 2005-12-29 |
published | 2005-12-29 |
reporter | rgod |
source | https://www.exploit-db.com/download/1395/ |
title | phpDocumentor <= 1.3.0 rc4 - Remote Commands Execution Exploit |
Nessus
NASL family | CGI abuses |
NASL id | PHPDOCUMENTOR_1_3_REMOTE_FILE_INCLUSION.NASL |
description | phpDocumentor is a automatic documentation generator for PHP. The remote host appears to be running the web-interface of phpDocumentor. This version does not properly sanitize user input in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20374 |
published | 2006-01-02 |
reporter | This script is Copyright (C) 2006-2018 Ferdy Riphagen |
source | https://www.tenable.com/plugins/nessus/20374 |
title | phpDocumentor <= 1.3.0 RC4 Local And Remote File Inclusion |
code |
|
References
- http://rgod.altervista.org/phpdocumentor_130rc4_incl_expl.html
- http://rgod.altervista.org/phpdocumentor_130rc4_incl_expl.html
- http://secunia.com/advisories/18248
- http://secunia.com/advisories/18248
- http://securityreason.com/securityalert/303
- http://securityreason.com/securityalert/303
- http://securitytracker.com/id?1015423
- http://securitytracker.com/id?1015423
- http://www.osvdb.org/22114
- http://www.osvdb.org/22114
- http://www.osvdb.org/22115
- http://www.osvdb.org/22115
- http://www.securityfocus.com/archive/1/420441/100/0/threaded
- http://www.securityfocus.com/archive/1/420441/100/0/threaded
- http://www.securityfocus.com/bid/16080
- http://www.securityfocus.com/bid/16080
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23902
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23902