Vulnerabilities > CVE-2006-2608 - Remote Script Execution vulnerability in Artmedic Webdesign Artmedic Newsletter 4.1

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
artmedic-webdesign
exploit available

Summary

artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as demonstrated by injecting PHP code into info.php.

Vulnerable Configurations

Part Description Count
Application
Artmedic_Webdesign
1

Exploit-Db

descriptionArtmedic Newsletter 4.1 Log.PHP Remote Script Execution Vulnerability. CVE-2006-2608. Webapps exploit for php platform
idEDB-ID:27900
last seen2016-02-03
modified2006-05-19
published2006-05-19
reporterC.Schmitz
sourcehttps://www.exploit-db.com/download/27900/
titleArtmedic Newsletter 4.1 Log.PHP Remote Script Execution Vulnerability