Vulnerabilities > CVE-2006-1839 - Unspecified vulnerability in PHP Album PHP Album 0.3.2.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | PHPAlbum 0.2.2/0.2.3/4.1 Language.PHP File Include Vulnerability. CVE-2006-1839. Webapps exploit for php platform |
id | EDB-ID:27643 |
last seen | 2016-02-03 |
modified | 2006-04-15 |
published | 2006-04-15 |
reporter | rgod |
source | https://www.exploit-db.com/download/27643/ |
title | PHPAlbum 0.2.2/0.2.3/4.1 Language.PHP File Include Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | PHPALBUM_DATA_DIR_FILE_INCLUDE.NASL |
description | The remote host is running phpAlbum, an open source web photo gallery written in PHP. The version of phpAlbum installed on the remote host fails to sanitize user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21236 |
published | 2006-04-17 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/21236 |
title | phpAlbum language.php data_dir Parameter Remote File Inclusion |
code |
|
References
- http://retrogod.altervista.org/phpalbum_0323_incl_xpl.html
- http://retrogod.altervista.org/phpalbum_0323_incl_xpl.html
- http://secunia.com/advisories/19661
- http://secunia.com/advisories/19661
- http://www.osvdb.org/24741
- http://www.osvdb.org/24741
- http://www.securityfocus.com/archive/1/431067/100/0/threaded
- http://www.securityfocus.com/archive/1/431067/100/0/threaded
- http://www.securityfocus.com/bid/17526
- http://www.securityfocus.com/bid/17526
- http://www.vupen.com/english/advisories/2006/1382
- http://www.vupen.com/english/advisories/2006/1382
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25846
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25846