Vulnerabilities > CVE-2006-4557 - Unspecified vulnerability in Robert Jewell Discloser 0.0.4
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
PHP remote file inclusion vulnerability in plugins/plugins.php in Bob Jewell Discloser 0.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the type parameter. NOTE: another researcher has stated that an attacker cannot control the type parameter. As of 20060901, CVE analysis concurs with the dispute
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://www.securityfocus.com/archive/1/443466/100/200/threaded
- http://www.securityfocus.com/archive/1/443466/100/200/threaded
- http://www.securityfocus.com/archive/1/443522/100/200/threaded
- http://www.securityfocus.com/archive/1/443522/100/200/threaded
- http://www.securityfocus.com/archive/1/443710/100/100/threaded
- http://www.securityfocus.com/archive/1/443710/100/100/threaded
- http://www.securityfocus.com/archive/1/444074/100/100/threaded
- http://www.securityfocus.com/archive/1/444074/100/100/threaded