Vulnerabilities > CVE-2006-5832 - Input Validation vulnerability in AIOCP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Exploit-Db
description AIOCP 1.3.x cp_show_page_help.php Path Disclosure. CVE-2006-5832. Webapps exploit for php platform id EDB-ID:28937 last seen 2016-02-03 modified 2006-11-06 published 2006-11-06 reporter laurent gaffie source https://www.exploit-db.com/download/28937/ title AIOCP 1.3.x cp_show_page_help.php Path Disclosure description AIOCP 1.3.x cp_show_ec_products.php Path Disclosure. CVE-2006-5832. Webapps exploit for php platform id EDB-ID:28936 last seen 2016-02-03 modified 2006-11-06 published 2006-11-06 reporter laurent gaffie source https://www.exploit-db.com/download/28936/ title AIOCP 1.3.x cp_show_ec_products.php Path Disclosure description AIOCP 1.3.x cp_dpage.php Path Disclosure. CVE-2006-5832 . Webapps exploit for php platform id EDB-ID:28935 last seen 2016-02-03 modified 2006-11-06 published 2006-11-06 reporter laurent gaffie source https://www.exploit-db.com/download/28935/ title AIOCP 1.3.x cp_dpage.php Path Disclosure