Vulnerabilities > CVE-2006-0940 - Input Validation vulnerability in Cynical Games Shoutlive 1.1.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ShoutLIVE <= 1.1.0 (savesettings.php) Remote Code Execution Exploit. CVE-2006-0940. Webapps exploit for php platform |
id | EDB-ID:1590 |
last seen | 2016-01-31 |
modified | 2006-03-18 |
published | 2006-03-18 |
reporter | DarkFig |
source | https://www.exploit-db.com/download/1590/ |
title | ShoutLIVE <= 1.1.0 savesettings.php Remote Code Execution Exploit |
Packetstorm
data source | https://packetstormsecurity.com/files/download/44492/EV0087.txt |
id | PACKETSTORM:44492 |
last seen | 2016-12-05 |
published | 2006-03-09 |
reporter | Aliaksandr Hartsuyeu |
source | https://packetstormsecurity.com/files/44492/EV0087.txt.html |
title | EV0087.txt |
References
- http://evuln.com/vulns/87/summary.html
- http://secunia.com/advisories/19047
- http://securityreason.com/securityalert/557
- http://www.osvdb.org/23482
- http://www.securityfocus.com/archive/1/426985/100/0/threaded
- http://www.securityfocus.com/bid/16857
- http://www.vupen.com/english/advisories/2006/0755
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24897