Vulnerabilities > CVE-2006-1477 - Remote File Include vulnerability in Turnkey web Tools PHP Live Helper 1.8
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. This vulnerability may affect all versions prior to 1.8 as well.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | CGI abuses |
NASL id | PHPLIVEHELPER_ABS_PATH_FILE_INCLUDES.NASL |
description | The remote host is running PHP Help Live, a commercial web-based real-time help tool written using PHP and MySQL. The version of PHP Help Live installed on the remote host fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21159 |
published | 2006-03-28 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21159 |
title | PHP Live Helper Multiple Remote File Inclusions |
code |
|
References
- http://secunia.com/advisories/19428
- http://www.osvdb.org/24193
- http://www.osvdb.org/24194
- http://www.osvdb.org/24195
- http://www.osvdb.org/24196
- http://www.osvdb.org/24197
- http://www.osvdb.org/24198
- http://www.osvdb.org/24199
- http://www.securityfocus.com/archive/1/428976/100/0/threaded
- http://www.securityfocus.com/archive/1/437648/100/0/threaded
- http://www.securityfocus.com/archive/1/437741/100/0/threaded
- http://www.securityfocus.com/bid/18509
- http://www.turnkeywebtools.com/forum/showthread.php?p=10415
- http://www.vupen.com/english/advisories/2006/1137
- http://www.worlddefacers.de/Public/WD-TMPLH.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25489