Vulnerabilities > CVE-2006-5125 - Remote File Include and Information Disclosure vulnerability in Joshua Muheim PHPmywebmin 1.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
joshua-muheim
exploit available

Summary

Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.

Vulnerable Configurations

Part Description Count
Application
Joshua_Muheim
1

Exploit-Db

  • descriptionphpMyWebmin 1.0 (window.php) Remote File Include Vulnerability. CVE-2006-5124,CVE-2006-5125. Webapps exploit for php platform
    fileexploits/php/webapps/2451.txt
    idEDB-ID:2451
    last seen2016-01-31
    modified2006-09-28
    platformphp
    port
    published2006-09-28
    reporterKernel-32
    sourcehttps://www.exploit-db.com/download/2451/
    titlephpMyWebmin 1.0 - window.php Remote File Include Vulnerability
    typewebapps
  • descriptionphpMyWebmin. CVE-2006-5124,CVE-2006-5125,CVE-2006-5181. Webapps exploit for php platform
    fileexploits/php/webapps/2462.txt
    idEDB-ID:2462
    last seen2016-01-31
    modified2006-09-30
    platformphp
    port
    published2006-09-30
    reporterMehmet Ince
    sourcehttps://www.exploit-db.com/download/2462/
    titlephpMyWebmin <= 1.0 - target Remote File Include Vulnerabilities
    typewebapps