Vulnerabilities > CVE-2006-5832 - Input Validation vulnerability in AIOCP

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
aiocp
exploit available

Summary

All In One Control Panel (AIOCP) 1.3.007 and earlier allows remote attackers to obtain the full path of the web server via certain requests to (1) public/code/cp_dpage.php, possibly involving the aiocp_dp[] parameter, (2) public/code/cp_show_ec_products.php, possibly involving the order_field[] parameter, and (3) public/code/cp_show_page_help.php, possibly involving the hp[] parameter, which reveal the path in various error messages.

Exploit-Db

  • descriptionAIOCP 1.3.x cp_show_page_help.php Path Disclosure. CVE-2006-5832. Webapps exploit for php platform
    idEDB-ID:28937
    last seen2016-02-03
    modified2006-11-06
    published2006-11-06
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28937/
    titleAIOCP 1.3.x cp_show_page_help.php Path Disclosure
  • descriptionAIOCP 1.3.x cp_show_ec_products.php Path Disclosure. CVE-2006-5832. Webapps exploit for php platform
    idEDB-ID:28936
    last seen2016-02-03
    modified2006-11-06
    published2006-11-06
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28936/
    titleAIOCP 1.3.x cp_show_ec_products.php Path Disclosure
  • descriptionAIOCP 1.3.x cp_dpage.php Path Disclosure. CVE-2006-5832 . Webapps exploit for php platform
    idEDB-ID:28935
    last seen2016-02-03
    modified2006-11-06
    published2006-11-06
    reporterlaurent gaffie
    sourcehttps://www.exploit-db.com/download/28935/
    titleAIOCP 1.3.x cp_dpage.php Path Disclosure