Vulnerabilities > CVE-2006-3983 - Remote File Include vulnerability in Ekilat LLC PHP(Reactor) 1.27Pl1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ekilat-llc
exploit available

Summary

PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter.

Vulnerable Configurations

Part Description Count
Application
Ekilat_Llc
1

Exploit-Db

descriptionPhpReactor 1.2.7pl1 (pathtohomedir) Remote Inclusion Vulnerability. CVE-2006-3983. Webapps exploit for php platform
fileexploits/php/webapps/2095.txt
idEDB-ID:2095
last seen2016-01-31
modified2006-07-31
platformphp
port
published2006-07-31
reporterCeNGiZ-HaN
sourcehttps://www.exploit-db.com/download/2095/
titlePhpReactor 1.2.7pl1 pathtohomedir Remote Inclusion Vulnerability
typewebapps