Vulnerabilities > CVE-2006-3069 - Unspecified vulnerability in Iglooweb Doublespeak 0.1

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
iglooweb
exploit available

Summary

PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and (3) hardware.php. NOTE: this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used

Vulnerable Configurations

Part Description Count
Application
Iglooweb
1

Exploit-Db

descriptionDoubleSpeak 0.1 Multiple Remote File Include Vulnerabilities. CVE-2006-3069. Webapps exploit for php platform
idEDB-ID:28016
last seen2016-02-03
modified2006-06-13
published2006-06-13
reporterR@1D3N
sourcehttps://www.exploit-db.com/download/28016/
titleDoubleSpeak 0.1 - Multiple Remote File Include Vulnerabilities