Vulnerabilities > CVE-2006-4889 - Unspecified vulnerability in Telekorn Signkorn Guestbook 1.1/1.2

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
telekorn
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.

Vulnerable Configurations

Part Description Count
Application
Telekorn
3

Exploit-Db

  • descriptionTelekorn Signkorn Guestbook 1.x help/de/adminhelp3.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28535
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28535/
    titleTelekorn Signkorn Guestbook 1.x help/de/adminhelp3.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/de/adminhelp2.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28534
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28534/
    titleTelekorn Signkorn Guestbook 1.x help/de/adminhelp2.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x smile.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28527
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28527/
    titleTelekorn Signkorn Guestbook 1.x smile.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x admin/index.php dir_path Parameter Remote File Inclusion. CVE-2006-4889 . Webapps exploit for php platform
    idEDB-ID:28539
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28539/
    titleTelekorn Signkorn Guestbook 1.x admin/index.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x admin/admin.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28541
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28541/
    titleTelekorn Signkorn Guestbook 1.x admin/admin.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x admin/config.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28540
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28540/
    titleTelekorn Signkorn Guestbook 1.x admin/config.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/en/adminhelp2.php dir_path Parameter Remote File Inclusion. CVE-2006-4889 . Webapps exploit for php platform
    idEDB-ID:28530
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28530/
    titleTelekorn Signkorn Guestbook 1.x help/en/adminhelp2.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/de/adminhelp0.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28532
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28532/
    titleTelekorn Signkorn Guestbook 1.x help/de/adminhelp0.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x admin/preview.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28537
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28537/
    titleTelekorn Signkorn Guestbook 1.x admin/preview.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x admin/log.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28538
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28538/
    titleTelekorn Signkorn Guestbook 1.x admin/log.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/en/adminhelp3.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28531
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28531/
    titleTelekorn Signkorn Guestbook 1.x help/en/adminhelp3.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28526
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28526/
    titleTelekorn Signkorn Guestbook 1.x help.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x entry.php dir_path Parameter Remote File Inclusion. CVE-2006-4889 . Webapps exploit for php platform
    idEDB-ID:28536
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28536/
    titleTelekorn Signkorn Guestbook 1.x entry.php dir_path Parameter Remote File Inclusion
  • descriptionSignkorn Guestbook <= 1.3 (dir_path) Remote File Include Vulnerability. CVE-2006-4788,CVE-2006-4889. Webapps exploit for php platform
    fileexploits/php/webapps/2354.txt
    idEDB-ID:2354
    last seen2016-01-31
    modified2006-09-12
    platformphp
    port
    published2006-09-12
    reporterSHiKaA
    sourcehttps://www.exploit-db.com/download/2354/
    titleSignkorn Guestbook <= 1.3 dir_path Remote File Include Vulnerability
    typewebapps
  • descriptionTelekorn Signkorn Guestbook 1.x help/de/adminhelp1.php dir_path Parameter Remote File Inclusion. CVE-2006-4889 . Webapps exploit for php platform
    idEDB-ID:28533
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28533/
    titleTelekorn Signkorn Guestbook 1.x help/de/adminhelp1.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x includes/functions.admin.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28524
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28524/
    titleTelekorn Signkorn Guestbook 1.x includes/functions.admin.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x includes/admin.inc.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28525
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28525/
    titleTelekorn Signkorn Guestbook 1.x includes/admin.inc.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x includes/functions.gb.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28523
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28523/
    titleTelekorn Signkorn Guestbook 1.x includes/functions.gb.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x index.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28522
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28522/
    titleTelekorn Signkorn Guestbook 1.x index.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/en/adminhelp1.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28529
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28529/
    titleTelekorn Signkorn Guestbook 1.x help/en/adminhelp1.php dir_path Parameter Remote File Inclusion
  • descriptionTelekorn Signkorn Guestbook 1.x help/en/adminhelp0.php dir_path Parameter Remote File Inclusion. CVE-2006-4889. Webapps exploit for php platform
    idEDB-ID:28528
    last seen2016-02-03
    modified2006-09-12
    published2006-09-12
    reporterThE_LeO
    sourcehttps://www.exploit-db.com/download/28528/
    titleTelekorn Signkorn Guestbook 1.x help/en/adminhelp0.php dir_path Parameter Remote File Inclusion