Vulnerabilities > CVE-2006-4349 - Unspecified vulnerability in Toenda Software Development Toendacms 1.0/Stable1.0.3

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
toenda-software-development
exploit available

Summary

PHP remote file inclusion vulnerability in ToendaCMS 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tcms_administer_site parameter to an unspecified script, probably index.php. NOTE: this issue has been disputed by a third party, who states that $tcms_administer_site is initialized to a constant value within index.php

Exploit-Db

descriptionToendaCMS 0.x/1.0.x TCMS_Administer Parameter Remote File Include Vulnerability. CVE-2006-4349. Webapps exploit for php platform
idEDB-ID:28417
last seen2016-02-03
modified2006-08-21
published2006-08-21
reporterYou_You
sourcehttps://www.exploit-db.com/download/28417/
titleToendaCMS 0.x/1.0.x TCMS_Administer Parameter Remote File Include Vulnerability