Vulnerabilities > CVE-2006-5786 - Local File Include vulnerability in E107 0.7.5

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
e107
nessus
exploit available

Summary

Directory traversal vulnerability in class2.php in e107 0.7.5 and earlier allows remote attackers to read and execute PHP code in arbitrary files via ".." sequences in the e107language_e107cookie cookie to gsitemap.php.

Vulnerable Configurations

Part Description Count
Application
E107
1

Exploit-Db

descriptione107. CVE-2006-5786. Webapps exploit for php platform
fileexploits/php/webapps/2711.php
idEDB-ID:2711
last seen2016-01-31
modified2006-11-04
platformphp
port
published2006-11-04
reporterKacper
sourcehttps://www.exploit-db.com/download/2711/
titlee107 <= 0.75 - e107language_e107cookie Local File Include Exploit
typewebapps

Nessus

NASL familyCGI abuses
NASL idE107_E107LANGUAGE_E107COOKIE_FILE_INCLUDE.NASL
descriptionThe
last seen2020-06-01
modified2020-06-02
plugin id23624
published2006-11-06
reporterThis script is Copyright (C) 2006-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/23624
titlee107 class2.php e107language_e107cookie Cookie Traversal Local File Inclusion