Vulnerabilities > CVE-2006-7079 - Improper Control of Dynamically-Managed Code Resources vulnerability in Exv2 Content Management System
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | exV2. CVE-2006-7079,CVE-2006-7080. Webapps exploit for php platform |
file | exploits/php/webapps/2415.php |
id | EDB-ID:2415 |
last seen | 2016-01-31 |
modified | 2006-09-22 |
platform | php |
port | |
published | 2006-09-22 |
reporter | rgod |
source | https://www.exploit-db.com/download/2415/ |
title | exV2 <= 2.0.4.3 - extract Remote Command Execution Exploit |
type | webapps |