Vulnerabilities > CVE-2006-6634 - Remote File Include vulnerability in ExtCalThai Mambo Component

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
mambo
exploit available

Summary

Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php, or (3) the CONFIG_EXT[LIB_DIR] parameter to lib/mail.inc.php.

Vulnerable Configurations

Part Description Count
Application
Mambo
1

Exploit-Db

  • descriptionMamboLaiThai ExtCalThai 0.9.1 admin_events.php CONFIG_EXT[LANGUAGES_DIR] Parameter Remote File Inclusion. CVE-2006-6634. Webapps exploit for php platform
    idEDB-ID:28792
    last seen2016-02-03
    modified2006-10-12
    published2006-10-12
    reporterk1tk4t
    sourcehttps://www.exploit-db.com/download/28792/
    titleMamboLaiThai ExtCalThai 0.9.1 - admin_events.php CONFIG_EXTLANGUAGES_DIR Parameter Remote File Inclusion
  • descriptionMamboLaiThai ExtCalThai 0.9.1 mail.inc.php CONFIG_EXT[LIB_DIR] Parameter Remote File Inclusion. CVE-2006-6634. Webapps exploit for php platform
    idEDB-ID:28793
    last seen2016-02-03
    modified2006-10-12
    published2006-10-12
    reporterk1tk4t
    sourcehttps://www.exploit-db.com/download/28793/
    titleMamboLaiThai ExtCalThai 0.9.1 - mail.inc.php CONFIG_EXTLIB_DIR Parameter Remote File Inclusion