Vulnerabilities > CVE-2006-4418 - Local File Include vulnerability in Wikepage 2006.2/2006.2A

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
wikepage
exploit available

Summary

Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file.

Vulnerable Configurations

Part Description Count
Application
Wikepage
2

Exploit-Db

descriptionWikepage Opus 10. CVE-2006-4418. Webapps exploit for php platform
fileexploits/php/webapps/2252.pl
idEDB-ID:2252
last seen2016-01-31
modified2006-08-24
platformphp
port
published2006-08-24
reporterHessam-x
sourcehttps://www.exploit-db.com/download/2252/
titleWikepage Opus 10 <= 2006.2a lng - Remote Command Execution Exploit
typewebapps