Vulnerabilities > CVE-2006-2863 - Remote File Include vulnerability in CS-Cart Class.cs_phpmailer.PHP

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
cs-cart
exploit available

Summary

PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter. Successful exploitation requires that "register_globals" is enabled.

Exploit-Db

descriptionCS-Cart. CVE-2006-2863. Webapps exploit for php platform
fileexploits/php/webapps/1872.txt
idEDB-ID:1872
last seen2016-01-31
modified2006-06-03
platformphp
port
published2006-06-03
reporterKacper
sourcehttps://www.exploit-db.com/download/1872/
titleCS-Cart <= 1.3.3 - classes_dir Remote File Include Vulnerability
typewebapps