Vulnerabilities > CVE-2006-4498 - Remote File Include vulnerability in PHPalbum.Net PHPalbum 0.2.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
phpalbum-net
exploit available

Summary

PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922.

Vulnerable Configurations

Part Description Count
Application
Phpalbum.Net
1

Exploit-Db

descriptionPortailPHP mod_phpalbum <= 2.1.5 (chemin) Remote Include Vuln. CVE-2006-4498. Webapps exploit for php platform
fileexploits/php/webapps/2271.txt
idEDB-ID:2271
last seen2016-01-31
modified2006-08-29
platformphp
port
published2006-08-29
reporterMehmet Ince
sourcehttps://www.exploit-db.com/download/2271/
titlePortailPHP mod_phpalbum <= 2.1.5 chemin Remote Include Vuln
typewebapps