Vulnerabilities > CVE-2006-4354 - Remote File Include vulnerability in Phome Empire Phome Empire CMS 3.7

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phome-empire
exploit available

Summary

PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the check_path parameter.

Vulnerable Configurations

Part Description Count
Application
Phome_Empire
1

Exploit-Db

descriptionEmpire CMS <= 3.7 (checklevel.php) Remote File Include Vulnerability. CVE-2006-4354. Webapps exploit for php platform
fileexploits/php/webapps/2239.txt
idEDB-ID:2239
last seen2016-01-31
modified2006-08-22
platformphp
port
published2006-08-22
reporterBob Linuson
sourcehttps://www.exploit-db.com/download/2239/
titleEmpire CMS <= 3.7 checklevel.php Remote File Include Vulnerability
typewebapps