Vulnerabilities > CVE-2006-6613 - Local File Include vulnerability in PhpAlbum Language.php

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpalbum-net
exploit available

Summary

Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.

Vulnerable Configurations

Part Description Count
Application
Phpalbum.Net
1

Exploit-Db

descriptionphpAlbum <= 0.4.1 Beta 6 (language.php) Local File Inclusion Exploit. CVE-2006-6613. Webapps exploit for php platform
fileexploits/php/webapps/2913.php
idEDB-ID:2913
last seen2016-01-31
modified2006-12-10
platformphp
port
published2006-12-10
reporterKacper
sourcehttps://www.exploit-db.com/download/2913/
titlephpAlbum <= 0.4.1 Beta 6 language.php Local File Inclusion Exploit
typewebapps