Vulnerabilities > CVE-2006-4065 - Remote Security vulnerability in Sapid Gallery

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
dmitry-sheiko
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php. Successful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Dmitry_Sheiko
1

Exploit-Db

descriptionSAPID Gallery <= 1.0 (root_path) Remote File Include Vulnerabilities. CVE-2006-4063,CVE-2006-4065. Webapps exploit for php platform
fileexploits/php/webapps/2130.txt
idEDB-ID:2130
last seen2016-01-31
modified2006-08-07
platformphp
port80
published2006-08-07
reporterKacper
sourcehttps://www.exploit-db.com/download/2130/
titleSAPID Gallery <= 1.0 root_path Remote File Include Vulnerabilities
typewebapps