Vulnerabilities > CVE-2006-4788 - Unspecified vulnerability in Telekorn Signkorn Guestbook 1.1/1.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN telekorn
exploit available
Summary
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Exploit-Db
description | Signkorn Guestbook <= 1.3 (dir_path) Remote File Include Vulnerability. CVE-2006-4788,CVE-2006-4889. Webapps exploit for php platform |
file | exploits/php/webapps/2354.txt |
id | EDB-ID:2354 |
last seen | 2016-01-31 |
modified | 2006-09-12 |
platform | php |
port | |
published | 2006-09-12 |
reporter | SHiKaA |
source | https://www.exploit-db.com/download/2354/ |
title | Signkorn Guestbook <= 1.3 dir_path Remote File Include Vulnerability |
type | webapps |