Vulnerabilities > CVE-2006-4656 - Remote File Include vulnerability in Web-Provence SL_Site Spaw_control.class.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
web-provence
exploit available

Summary

PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.

Vulnerable Configurations

Part Description Count
Application
Web-Provence
1

Exploit-Db

  • descriptionSL_Site <= 1.0 (spaw_root) Remote File Include Vulnerability. CVE-2006-4656,CVE-2006-5291. Webapps exploit for php platform
    fileexploits/php/webapps/2317.txt
    idEDB-ID:2317
    last seen2016-01-31
    modified2006-09-07
    platformphp
    port
    published2006-09-07
    reporterKw3[R]Ln
    sourcehttps://www.exploit-db.com/download/2317/
    titleSL_Site <= 1.0 spaw_root Remote File Include Vulnerability
    typewebapps
  • descriptionDownload-Engine <= 1.4.2 (spaw) Remote File Include Vulnerability. CVE-2006-4656,CVE-2006-5291. Webapps exploit for php platform
    fileexploits/php/webapps/2521.txt
    idEDB-ID:2521
    last seen2016-01-31
    modified2006-10-12
    platformphp
    port
    published2006-10-12
    reporterv1per-haCker
    sourcehttps://www.exploit-db.com/download/2521/
    titleDownload-Engine <= 1.4.2 spaw Remote File Include Vulnerability
    typewebapps