Vulnerabilities > CVE-2006-4963 - Unspecified vulnerability in Exponent CMS 0.96.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code through session files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Exponent CMS <= 0.96.3 (view) Remote Command Execution Exploit. CVE-2006-4963. Webapps exploit for php platform |
file | exploits/php/webapps/2391.php |
id | EDB-ID:2391 |
last seen | 2016-01-31 |
modified | 2006-09-19 |
platform | php |
port | |
published | 2006-09-19 |
reporter | rgod |
source | https://www.exploit-db.com/download/2391/ |
title | Exponent CMS <= 0.96.3 view Remote Command Execution Exploit |
type | webapps |
Nessus
NASL family | CGI abuses |
NASL id | EXPONENT_VIEW_FILE_INCLUDE.NASL |
description | The remote host is running Exponent CMS, an open source content management system written in PHP. The version of Exponent CMS installed on the remote host fails to properly sanitize user-supplied input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22412 |
published | 2006-09-19 |
reporter | This script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/22412 |
title | Exponent CMS index.php view Parameter Local File Inclusion |
code |
|
References
- http://secunia.com/advisories/22003
- http://secunia.com/advisories/22003
- http://www.osvdb.org/29024
- http://www.osvdb.org/29024
- http://www.securityfocus.com/bid/20111
- http://www.securityfocus.com/bid/20111
- http://www.vupen.com/english/advisories/2006/3708
- http://www.vupen.com/english/advisories/2006/3708
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29077
- https://www.exploit-db.com/exploits/2391
- https://www.exploit-db.com/exploits/2391