Vulnerabilities > CVE-2006-4085 - Remote Security vulnerability in The Search Engine Project

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
olaf-noehring
exploit available

Summary

PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to pagenavigation.php, a different vector than CVE-2006-4055. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Olaf_Noehring
1

Exploit-Db

descriptionTSEP <= 0.942 (copyright.php) Remote Inclusion Vulnerability. CVE-2006-3993,CVE-2006-4055,CVE-2006-4085. Webapps exploit for php platform
fileexploits/php/webapps/2098.txt
idEDB-ID:2098
last seen2016-01-31
modified2006-08-01
platformphp
port
published2006-08-01
reporterPhilipp Niedziela
sourcehttps://www.exploit-db.com/download/2098/
titleTSEP <= 0.942 copyright.php Remote Inclusion Vulnerability
typewebapps