Vulnerabilities > CVE-2006-2877 - Remote File Include vulnerability in Sangwan KIM Bookmark4U 2.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sangwan-kim
exploit available

Summary

PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.

Vulnerable Configurations

Part Description Count
Application
Sangwan_Kim
1

Exploit-Db

  • descriptionBookmark4U 2.0 inc/config.php env[include_prefix] Parameter Remote File Inclusion. CVE-2006-2877. Webapps exploit for php platform
    idEDB-ID:27974
    last seen2016-02-03
    modified2006-06-05
    published2006-06-05
    reporterSnIpEr_SA
    sourcehttps://www.exploit-db.com/download/27974/
    titleBookmark4U 2.0 - inc/config.php envinclude_prefix Parameter Remote File Inclusion
  • descriptionBookmark4U 2.0 inc/dbase.php env[include_prefix] Parameter Remote File Inclusion. CVE-2006-2877. Webapps exploit for php platform
    idEDB-ID:27973
    last seen2016-02-03
    modified2006-06-05
    published2006-06-05
    reporterSnIpEr_SA
    sourcehttps://www.exploit-db.com/download/27973/
    titleBookmark4U 2.0 - inc/dbase.php envinclude_prefix Parameter Remote File Inclusion
  • descriptionBookmark4U 2.0 inc/function.php env[include_prefix] Parameter Remote File Inclusion. CVE-2006-2877. Webapps exploit for php platform
    idEDB-ID:27976
    last seen2016-02-03
    modified2006-06-05
    published2006-06-05
    reporterSnIpEr_SA
    sourcehttps://www.exploit-db.com/download/27976/
    titleBookmark4U 2.0 - inc/function.php envinclude_prefix Parameter Remote File Inclusion
  • descriptionBookmark4U 2.0 inc/common.php env[include_prefix] Parameter Remote File Inclusion. CVE-2006-2877 . Webapps exploit for php platform
    idEDB-ID:27975
    last seen2016-02-03
    modified2006-06-05
    published2006-06-05
    reporterSnIpEr_SA
    sourcehttps://www.exploit-db.com/download/27975/
    titleBookmark4U 2.0 - inc/common.php envinclude_prefix Parameter Remote File Inclusion