Vulnerabilities > CVE-2006-2730 - Remote File Include vulnerability in HOT Open Tickets HOT Open Tickets 2F20041101

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
hot-open-tickets
exploit available

Summary

PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability.

Vulnerable Configurations

Part Description Count
Application
Hot_Open_Tickets
1

Exploit-Db

descriptionHot Open Tickets <= 11012004 (CLASS_PATH) Remote Include Vuln. CVE-2006-2730. Webapps exploit for php platform
fileexploits/php/webapps/1835.txt
idEDB-ID:1835
last seen2016-01-31
modified2006-05-27
platformphp
port
published2006-05-27
reporterKacper
sourcehttps://www.exploit-db.com/download/1835/
titleHot Open Tickets <= 11012004 - CLASS_PATH Remote Include Vuln
typewebapps