Vulnerabilities > CVE-2006-2682 - Remote Security vulnerability in Back-End CMS 0.7.2.1

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
back-end
exploit available

Summary

PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter.

Vulnerable Configurations

Part Description Count
Application
Back-End
1

Exploit-Db

descriptionBack-End CMS <= 0.7.2.2 (BE_config.php) Remote Include Vulnerability. CVE-2006-2682. Webapps exploit for php platform
fileexploits/php/webapps/1825.txt
idEDB-ID:1825
last seen2016-01-31
modified2006-05-25
platformphp
port
published2006-05-25
reporterKacper
sourcehttps://www.exploit-db.com/download/1825/
titleBack-End CMS <= 0.7.2.2 BE_config.php Remote Include Vulnerability
typewebapps