Vulnerabilities > CVE-2006-5731 - Arbitrary Code Injection vulnerability in Lithium CMS Lithium CMS
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Lithium CMS <= 4.04c (classes/index.php) Local File Include Exploit. CVE-2006-5731. Webapps exploit for php platform |
file | exploits/php/webapps/2702.php |
id | EDB-ID:2702 |
last seen | 2016-01-31 |
modified | 2006-11-02 |
platform | php |
port | |
published | 2006-11-02 |
reporter | Kacper |
source | https://www.exploit-db.com/download/2702/ |
title | Lithium CMS <= 4.04c classes/index.php Local File Include Exploit |
type | webapps |