Vulnerabilities > CVE-2006-5429 - Remote File Include vulnerability in Brim

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
barry-nauta
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter in template.tpl.php in (1) templates/barrel/, (2) templates/sidebar/, (3) templates/text-only, (4) templates/slashdot/, (5) templates/penguin/, (6) templates/pda/, (7) templates/oerdec/, (8) templates/nifty/, (9) templates/mylook, and (10) templates/barry/.

Vulnerable Configurations

Part Description Count
Application
Barry_Nauta
1

Exploit-Db

descriptionBrim <= 1.2.1 (renderer) Multiple Remote File Include Vulnerabilities. CVE-2006-5429. Webapps exploit for php platform
fileexploits/php/webapps/2589.txt
idEDB-ID:2589
last seen2016-01-31
modified2006-10-17
platformphp
port
published2006-10-17
reportermdx
sourcehttps://www.exploit-db.com/download/2589/
titleBrim <= 1.2.1 renderer Multiple Remote File Include Vulnerabilities
typewebapps