Vulnerabilities > CVE-2006-4437 - PHP Code Injection vulnerability in Tagger LE

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
venture-nine
exploit available

Summary

Eval injection vulnerability in Tagger LE allows remote attackers to execute arbitrary PHP code via the query string in (1) tags.php, (2) sign.php, and (3) admin/index.php.

Vulnerable Configurations

Part Description Count
Application
Venture_Nine
1

Exploit-Db

descriptionTagger Luxury Edition (BBCodeFile) Remote File Include Vulnerability. CVE-2006-4437. Webapps exploit for php platform
idEDB-ID:2157
last seen2016-01-31
modified2006-08-09
published2006-08-09
reporterMorgan
sourcehttps://www.exploit-db.com/download/2157/
titleTagger Luxury Edition BBCodeFile Remote File Include Vulnerability