Vulnerabilities > CVE-2006-0891 - Unspecified vulnerability in Nocc 1.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.
Exploit-Db
description | NOCC Webmail <= 1.0 (Local Inclusion) Remote Code Execution Exploit. CVE-2006-0891. Webapps exploit for php platform |
id | EDB-ID:1522 |
last seen | 2016-01-31 |
modified | 2006-02-23 |
published | 2006-02-23 |
reporter | rgod |
source | https://www.exploit-db.com/download/1522/ |
title | NOCC Webmail <= 1.0 Local Inclusion Remote Code Execution Exploit |
Nessus
NASL family | CGI abuses |
NASL id | NOCC_10.NASL |
description | The remote host is running NOCC, an open source webmail application written in PHP. The installed version of NOCC is affected by a local file include flaw because it fails to sanitize user input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20974 |
published | 2006-02-25 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/20974 |
title | NOCC <= 1.0 Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0418.html
- http://retrogod.altervista.org/noccw_10_incl_xpl.html
- http://retrogod.altervista.org/noccw_10_incl_xpl.html
- http://secunia.com/advisories/16921
- http://secunia.com/advisories/16921
- http://securitytracker.com/id?1015671
- http://securitytracker.com/id?1015671
- http://www.osvdb.org/23416
- http://www.osvdb.org/23416
- http://www.osvdb.org/23417
- http://www.osvdb.org/23417
- http://www.osvdb.org/23418
- http://www.osvdb.org/23418
- http://www.osvdb.org/23419
- http://www.osvdb.org/23419
- http://www.securityfocus.com/bid/16793
- http://www.securityfocus.com/bid/16793
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24934
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24934