Vulnerabilities > CVE-2006-5124 - Remote File Include and Information Disclosure vulnerability in Joshua Muheim PHPmywebmin 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
joshua-muheim
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.

Vulnerable Configurations

Part Description Count
Application
Joshua_Muheim
1

Exploit-Db

  • descriptionphpMyWebmin 1.0 (window.php) Remote File Include Vulnerability. CVE-2006-5124,CVE-2006-5125. Webapps exploit for php platform
    fileexploits/php/webapps/2451.txt
    idEDB-ID:2451
    last seen2016-01-31
    modified2006-09-28
    platformphp
    port
    published2006-09-28
    reporterKernel-32
    sourcehttps://www.exploit-db.com/download/2451/
    titlephpMyWebmin 1.0 - window.php Remote File Include Vulnerability
    typewebapps
  • descriptionphpMyWebmin. CVE-2006-5124,CVE-2006-5125,CVE-2006-5181. Webapps exploit for php platform
    fileexploits/php/webapps/2462.txt
    idEDB-ID:2462
    last seen2016-01-31
    modified2006-09-30
    platformphp
    port
    published2006-09-30
    reporterMehmet Ince
    sourcehttps://www.exploit-db.com/download/2462/
    titlephpMyWebmin <= 1.0 - target Remote File Include Vulnerabilities
    typewebapps