Vulnerabilities > CVE-2006-5505 - Remote File Include vulnerability in Ben3W 2Bgal 3.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ben3w
exploit available

Summary

Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the lang parameter to (1) admin/configuration.inc.php, (2) admin/creer_album.inc.php, (3) admin/changepwd.php.inc, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Ben3W
1

Exploit-Db

description2BGal 3.0 (admin/configuration.inc.php) Local Inclusion Exploit. CVE-2006-5505. Webapps exploit for php platform
idEDB-ID:2698
last seen2016-01-31
modified2006-11-01
published2006-11-01
reporterKw3[R]Ln
sourcehttps://www.exploit-db.com/download/2698/
title2BGal 3.0 admin/configuration.inc.php Local Inclusion Exploit