Vulnerabilities > CVE-2006-1645 - Unspecified vulnerability in Reloadcms

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
reloadcms
exploit available

Summary

Cross-site scripting (XSS) vulnerability in Anton Vlasov and Rostislav Gaitkuloff ReloadCMS 1.2.5 and earlier allows remote attackers to inject arbitrary web script or HTML and gain leverage to execute arbitrary PHP code via the User-Agent HTTP header, which is displayed by admin/modules/general/statistic.php in the administration panel.

Exploit-Db

descriptionReloadCMS <= 1.2.5 Cross Site Scripting / Remote Code Execution Exploit. CVE-2006-1645. Webapps exploit for php platform
idEDB-ID:1631
last seen2016-01-31
modified2006-04-02
published2006-04-02
reporterrgod
sourcehttps://www.exploit-db.com/download/1631/
titleReloadCMS <= 1.2.5 - Cross-Site Scripting / Remote Code Execution Exploit