Vulnerabilities > CVE-2006-5421 - Unspecified vulnerability in WSN Forum WSN Forum

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
wsn-forum
exploit available

Summary

WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability.

Vulnerable Configurations

Part Description Count
Application
Wsn_Forum
1

Exploit-Db

descriptionWSN Forum <= 1.3.4 (prestart.php) Remote Code Execution Exploit. CVE-2006-5421. Webapps exploit for php platform
fileexploits/php/webapps/2583.php
idEDB-ID:2583
last seen2016-01-31
modified2006-10-17
platformphp
port
published2006-10-17
reporterKacper
sourcehttps://www.exploit-db.com/download/2583/
titleWSN Forum <= 1.3.4 prestart.php Remote Code Execution Exploit
typewebapps