Vulnerabilities > CVE-2006-4437 - PHP Code Injection vulnerability in Tagger LE
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Tagger Luxury Edition (BBCodeFile) Remote File Include Vulnerability. CVE-2006-4437. Webapps exploit for php platform |
id | EDB-ID:2157 |
last seen | 2016-01-31 |
modified | 2006-08-09 |
published | 2006-08-09 |
reporter | Morgan |
source | https://www.exploit-db.com/download/2157/ |
title | Tagger Luxury Edition BBCodeFile Remote File Include Vulnerability |
References
- http://secunia.com/advisories/21449
- http://secunia.com/secunia_research/2006-62/advisory/
- http://securityreason.com/securityalert/1584
- http://www.osvdb.org/28755
- http://www.osvdb.org/28756
- http://www.osvdb.org/28757
- http://www.securityfocus.com/archive/1/446010/100/0/threaded
- http://www.securityfocus.com/bid/20023
- http://www.vupen.com/english/advisories/2006/3606
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28941