Vulnerabilities > CVE-2006-6869 - Local File Include vulnerability in MDForum PNSVLang Parameter

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
maxdev
critical
exploit available

Summary

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

Vulnerable Configurations

Part Description Count
Application
Maxdev
1

Exploit-Db

descriptionMDForum <= 2.0.1 (PNSVlang) Remote Code Execution Exploit. CVE-2006-6869. Webapps exploit for php platform
fileexploits/php/webapps/3057.php
idEDB-ID:3057
last seen2016-01-31
modified2006-12-31
platformphp
port
published2006-12-31
reporterKacper
sourcehttps://www.exploit-db.com/download/3057/
titleMDForum <= 2.0.1 PNSVlang Remote Code Execution Exploit
typewebapps