Vulnerabilities > CVE-2006-6764 - Remote File Include vulnerability in Keep IT Simple Guest Book Keep IT Simple Guest Book 5.0

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
keep-it-simple-guest-book
exploit available

Summary

PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter. Successful exploitation requires executing PHP through CGI.

Exploit-Db

descriptionKISGB <= 5.1.1 (authenticate.php) Remote File Include Vulnerability. CVE-2006-6763,CVE-2006-6764,CVE-2008-1635. Webapps exploit for php platform
fileexploits/php/webapps/2979.txt
idEDB-ID:2979
last seen2016-01-31
modified2006-12-22
platformphp
port
published2006-12-22
reportermdx
sourcehttps://www.exploit-db.com/download/2979/
titleKISGB <= 5.1.1 authenticate.php Remote File Include Vulnerability
typewebapps