Vulnerabilities > CVE-2006-5232 - Unspecified vulnerability in Isearch 2.16
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN isearch
exploit available
Summary
Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5) google_sitemap.php, (6) stats.php, or (7) auto_spider_img.php. NOTE: this issue has been disputed by a third party who shows that $isearch_path is set to a constant value. CVE analysis as of 20061010 is inconclusive, although the original researcher is known to make mistakes
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | ISearch 2.16 ISEARCH_PATH Parameter Remote File Include Vulnerability. CVE-2006-5232. Webapps exploit for php platform |
id | EDB-ID:28772 |
last seen | 2016-02-03 |
modified | 2006-10-09 |
published | 2006-10-09 |
reporter | MoHaNdKo |
source | https://www.exploit-db.com/download/28772/ |
title | ISearch 2.16 ISEARCH_PATH Parameter Remote File Include Vulnerability |