Vulnerabilities > CVE-2006-3323 - Cross-Site Scripting vulnerability in Mastersfusion MF Piadas 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mastersfusion
exploit available

Summary

PHP remote file inclusion vulnerability in admin/admin.php in MF Piadas 1.0 allows remote attackers to execute arbitrary PHP code via the page parameter. NOTE: the same vector can be used for cross-site scripting, but CVE analysis suggests that this is resultant from file inclusion of HTML or script.

Vulnerable Configurations

Part Description Count
Application
Mastersfusion
1

Exploit-Db

  • descriptionMF Piadas 1.0 Admin.PHP Remote File Include Vulnerability. CVE-2006-3323. Webapps exploit for php platform
    idEDB-ID:28117
    last seen2016-02-03
    modified2006-06-27
    published2006-06-27
    reporterbotan
    sourcehttps://www.exploit-db.com/download/28117/
    titleMF Piadas 1.0 Admin.PHP Remote File Include Vulnerability
  • descriptionMF Piadas 1.0 Admin.PHP Cross-Site Scripting Vulnerability. CVE-2006-3323. Webapps exploit for php platform
    idEDB-ID:28115
    last seen2016-02-03
    modified2006-06-27
    published2006-06-27
    reporterbotan
    sourcehttps://www.exploit-db.com/download/28115/
    titleMF Piadas 1.0 Admin.PHP Cross-Site Scripting Vulnerability