Vulnerabilities > CVE-2006-0852 - Unspecified vulnerability in Devscripts Admbook
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Admbook <= 1.2.2 (X-Forwarded-For) Remote Command Execution Exploit. CVE-2006-0852. Webapps exploit for php platform |
file | exploits/php/webapps/1512.pl |
id | EDB-ID:1512 |
last seen | 2016-01-31 |
modified | 2006-02-19 |
platform | php |
port | |
published | 2006-02-19 |
reporter | rgod |
source | https://www.exploit-db.com/download/1512/ |
title | Admbook <= 1.2.2 X-Forwarded-For Remote Command Execution Exploit |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | ADMBOOK_CMD_EXEC.NASL |
description | The remote host is running AdmBook, a PHP-based guestbook. The remote version of this software is prone to remote PHP code injection due to a lack of sanitization of the HTTP header |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21080 |
published | 2006-03-15 |
reporter | This script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/21080 |
title | Admbook content-data.php X-Forwarded-For Header Arbitrary PHP Code Injection |
code |
|
References
- http://secunia.com/advisories/18930
- http://secunia.com/advisories/18930
- http://www.securityfocus.com/bid/16753
- http://www.securityfocus.com/bid/16753
- http://www.vupen.com/english/advisories/2006/0663
- http://www.vupen.com/english/advisories/2006/0663
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24771
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24771
- https://www.exploit-db.com/exploits/1512
- https://www.exploit-db.com/exploits/1512