Vulnerabilities > CVE-2006-0714 - Remote File Include vulnerability in Flyspray 0.9.7

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
flyspray
nessus
exploit available

Summary

Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the adodbpath parameter.

Vulnerable Configurations

Part Description Count
Application
Flyspray
1

Exploit-Db

descriptionFlySpray 0.9.7 (install-0.9.7.php) Remote Commands Execution Exploit. CVE-2006-0714. Webapps exploit for php platform
idEDB-ID:1494
last seen2016-01-31
modified2006-02-13
published2006-02-13
reporterrgod
sourcehttps://www.exploit-db.com/download/1494/
titleFlySpray 0.9.7 install-0.9.7.php Remote Commands Execution Exploit

Nessus

NASL familyCGI abuses
NASL idFLYSPRAY_ADODBPATH_FILE_INCLUDE.NASL
descriptionThe remote host is running Flyspray, an open source, web-based, bug tracking system written in PHP. The installed version of Flyspray contains an installation script that does not require authentication and that fails to sanitize user input to the
last seen2020-06-01
modified2020-06-02
plugin id20929
published2006-02-16
reporterThis script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/20929
titleFlyspray install-0.9.7.php adodbpath Parameter Remote File Inclusion