Vulnerabilities > CVE-2006-7132 - Directory Traversal vulnerability in Cynux Softwares PHPmydesk 1.0Beta

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
cynux-softwares
critical
exploit available

Summary

Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary local files via the pmdlang parameter to viewticket.php.

Vulnerable Configurations

Part Description Count
Application
Cynux_Softwares
1

Exploit-Db

descriptionPHPMyDesk 1.0beta (viewticket.php) Local Include Exploit. CVE-2006-7132. Webapps exploit for php platform
fileexploits/php/webapps/2664.pl
idEDB-ID:2664
last seen2016-01-31
modified2006-10-28
platformphp
port
published2006-10-28
reporterKw3[R]Ln
sourcehttps://www.exploit-db.com/download/2664/
titlePHPMyDesk 1.0beta viewticket.php Local Include Exploit
typewebapps