Vulnerabilities > CVE-2006-4210 - Unspecified vulnerability in Andreas Kansok PHPay 2.02/2.02.1

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
andreas-kansok
exploit available

Summary

nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Andreas_Kansok
2

Exploit-Db

descriptionphPay <= 2.02 (nu_mail.inc.php) Remote mail() Injection Exploit. CVE-2006-4210. Webapps exploit for php platform
fileexploits/php/webapps/2181.pl
idEDB-ID:2181
last seen2016-01-31
modified2006-08-14
platformphp
port80
published2006-08-14
reporterbeford
sourcehttps://www.exploit-db.com/download/2181/
titlephPay <= 2.02 nu_mail.inc.php Remote mail Injection Exploit
typewebapps