Vulnerabilities > CVE-2006-5433 - Remote File Include vulnerability in Timm Maass Alice CMS 0.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
timm-maass
exploit available

Summary

PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[local_root] parameter.

Vulnerable Configurations

Part Description Count
Application
Timm_Maass
1

Exploit-Db

descriptionALiCE-CMS 0.1 (CONFIG[local_root]) Remote File Include Vulnerability. CVE-2006-5433. Webapps exploit for php platform
fileexploits/php/webapps/2582.txt
idEDB-ID:2582
last seen2016-01-31
modified2006-10-17
platformphp
port
published2006-10-17
reporternuffsaid
sourcehttps://www.exploit-db.com/download/2582/
titleALiCE-CMS 0.1 - CONFIGlocal_root Remote File Include Vulnerability
typewebapps