Vulnerabilities > CVE-2006-0824 - Unspecified vulnerability in Geeklog
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN geeklog
nessus
Summary
Multiple unspecified vulnerabilities in lib-common.php in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to include arbitrary local files and execute arbitrary code via (1) absolute paths in unspecified parameters and (2) the language cookie, as demonstrated for code execution using error.log.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | CGI abuses |
NASL id | GEEKLOG_140SR1.NASL |
description | The installed version of Geeklog suffers from a number of SQL injection and local file flaws due to a failure of the application to sanitize user-supplied input. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20959 |
published | 2006-02-22 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20959 |
title | Geeklog < 1.3.11sr4 / 1.4.0sr1 Multiple Remote Vulnerabilities (LFI, SQLi) |
code |
|
References
- http://secunia.com/advisories/18920
- http://secunia.com/advisories/18920
- http://www.geeklog.net/article.php/geeklog-1.4.0sr1
- http://www.geeklog.net/article.php/geeklog-1.4.0sr1
- http://www.gulftech.org/?node=research&article_id=00102-02192006
- http://www.gulftech.org/?node=research&article_id=00102-02192006
- http://www.osvdb.org/23349
- http://www.osvdb.org/23349
- http://www.securityfocus.com/archive/1/425506/100/0/threaded
- http://www.securityfocus.com/archive/1/425506/100/0/threaded
- http://www.securityfocus.com/bid/16755
- http://www.securityfocus.com/bid/16755
- http://www.vupen.com/english/advisories/2006/0661
- http://www.vupen.com/english/advisories/2006/0661