Vulnerabilities > CVE-2006-4837 - Unspecified vulnerability in Codeworx Technologies Dcp-Portal Se6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN codeworx-technologies
exploit available
Summary
Multiple PHP remote file inclusion vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) library/lib.php and (2) library/editor/editor.php. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
id | EDB-ID:1905 |
References
- http://securityreason.com/securityalert/1585
- http://securityreason.com/securityalert/1585
- http://www.securityfocus.com/archive/1/437510/100/200/threaded
- http://www.securityfocus.com/archive/1/437510/100/200/threaded
- http://www.securityfocus.com/archive/1/445996/100/0/threaded
- http://www.securityfocus.com/archive/1/445996/100/0/threaded
- http://www.securityfocus.com/bid/20024
- http://www.securityfocus.com/bid/20024
- https://www.exploit-db.com/exploits/1905
- https://www.exploit-db.com/exploits/1905