Vulnerabilities > CVE-2006-1200 - Unspecified vulnerability in Daverave Link Bank
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Direct static code injection vulnerability in add_link.txt in daverave Link Bank allows remote attackers to execute arbitrary PHP code via the url_name parameter, which is not sanitized before being stored in links.txt, which is later used in an include statement.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://secunia.com/advisories/19154
- http://secunia.com/advisories/19154
- http://securityreason.com/securityalert/553
- http://securityreason.com/securityalert/553
- http://www.osvdb.org/23750
- http://www.osvdb.org/23750
- http://www.securityfocus.com/archive/1/426932/100/0/threaded
- http://www.securityfocus.com/archive/1/426932/100/0/threaded
- http://www.securityfocus.com/bid/17004
- http://www.securityfocus.com/bid/17004
- http://www.vupen.com/english/advisories/2006/0885
- http://www.vupen.com/english/advisories/2006/0885