Vulnerabilities > CVE-2006-4422 - Unspecified vulnerability in Jetbox CMS 2.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN jetbox
exploit available
Summary
PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary PHP code via a URL in the relative_script_path parameter, a different vector than CVE-2006-2270. NOTE: this issue has been disputed, and as of 20060830, CVE analysis concurs with the dispute. In addition, it is likely that the vulnerability is actually in a third party module, phpDig 1.8.8
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Jetbox CMS 2.1 Search_function.PHP Remote File Include Vulnerability. CVE-2006-4422. Webapps exploit for php platform |
id | EDB-ID:28431 |
last seen | 2016-02-03 |
modified | 2006-08-26 |
published | 2006-08-26 |
reporter | D3nGeR |
source | https://www.exploit-db.com/download/28431/ |
title | Jetbox CMS 2.1 - Search_function.PHP Remote File Include Vulnerability |
References
- http://securitytracker.com/id?1016765
- http://securitytracker.com/id?1016765
- http://www.attrition.org/pipermail/vim/2006-August/000997.html
- http://www.attrition.org/pipermail/vim/2006-August/000997.html
- http://www.attrition.org/pipermail/vim/2006-August/001003.html
- http://www.attrition.org/pipermail/vim/2006-August/001003.html
- http://www.osvdb.org/28299
- http://www.osvdb.org/28299
- http://www.securityfocus.com/archive/1/444422/100/0/threaded
- http://www.securityfocus.com/archive/1/444422/100/0/threaded
- http://www.securityfocus.com/archive/1/444527/100/0/threaded
- http://www.securityfocus.com/archive/1/444527/100/0/threaded
- http://www.securityfocus.com/archive/1/444640/100/0/threaded
- http://www.securityfocus.com/archive/1/444640/100/0/threaded
- http://www.securityfocus.com/archive/1/444740/100/0/threaded
- http://www.securityfocus.com/archive/1/444740/100/0/threaded
- http://www.securityfocus.com/archive/1/444822/100/0/threaded
- http://www.securityfocus.com/archive/1/444822/100/0/threaded
- http://www.securityfocus.com/archive/1/444826/100/0/threaded
- http://www.securityfocus.com/archive/1/444826/100/0/threaded
- http://www.securityfocus.com/bid/19722
- http://www.securityfocus.com/bid/19722
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28588
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28588