Vulnerabilities > CVE-2006-5554 - Remote File Include vulnerability in ImageView

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
blackdot
exploit available

Summary

Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/plain .gif file containing PHP code, which is executed by index.php.

Vulnerable Configurations

Part Description Count
Application
Blackdot
1

Exploit-Db

descriptionImageview <= 5 (Cookie/index.php) Remote Local Include Exploit. CVE-2006-5554. Webapps exploit for php platform
fileexploits/php/webapps/2647.php
idEDB-ID:2647
last seen2016-01-31
modified2006-10-25
platformphp
port
published2006-10-25
reporterKacper
sourcehttps://www.exploit-db.com/download/2647/
titleImageview <= 5 Cookie/index.php Remote Local Include Exploit
typewebapps