Vulnerabilities > CVE-2006-4237 - Remote Pageheaderdefault.Inc.PHP Remote File Include vulnerability in Invisionix Roaming System

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
invisionix-systems
exploit available

Summary

PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter.

Vulnerable Configurations

Part Description Count
Application
Invisionix_Systems
1

Exploit-Db

descriptionIRSR <= 0.2 (_sysSessionPath) Remote File Include Vulnerability. CVE-2006-4237. Webapps exploit for php platform
fileexploits/php/webapps/2199.txt
idEDB-ID:2199
last seen2016-01-31
modified2006-08-17
platformphp
port
published2006-08-17
reporterKacper
sourcehttps://www.exploit-db.com/download/2199/
titleIRSR <= 0.2 _sysSessionPath Remote File Include Vulnerability
typewebapps